Junglewise Threat Intelligence

CVE-2026-73370: Apache Syncope authorization bypass in delegated administration

CVE-2026-73370 · Severity: critical · CVSS 9.8 · Published 2026-09-14

Vendors: Apache.

Executive brief

Apache Syncope is an identity and access management platform that handles user provisioning and administrative delegation. The Reconciliation service's pull and push operations have incomplete authorization checks, allowing administrators without proper permissions to execute sensitive operations. This could allow an attacker with partial admin access to escalate privileges and modify user accounts or system configurations beyond their authorized scope.

Technical details

This is an authorization bypass vulnerability in Apache Syncope's Reconciliation service, where delegated administration security checks are incomplete in the pull and push operations. An attacker with administrative privileges but lacking specific entitlements can bypass authorization controls to perform operations they should not have access to. The vulnerability affects versions 3.0.0-M0 through 3.0.16, 4.0.0-M0 through 4.0.7, and 4.1.0-M0 through 4.1.2. Patches are available in versions 4.0.8 and 4.1.3. Attack requires network access and valid admin credentials with insufficient privilege validation during reconciliation operations.

Affected products

  • Apache Syncope 3.0.0-M0 through 3.0.16, 4.0.0-M0 through 4.0.7, 4.1.0-M0 through 4.1.2

Timeline

  • 2026-09-14: disclosed
  • 2026-09-14: patched: Fixed in versions 4.0.8 and 4.1.3

References