Junglewise Threat Intelligence

CVE-2026-73470: Apache Syncope privilege escalation in delegation management

CVE-2026-73470 · Severity: critical · CVSS 9.8 · Published 2026-09-14

Vendors: Apache.

Executive brief

Apache Syncope is an open-source identity management platform used to manage user accounts, roles, and access control across organizations. A privilege escalation vulnerability allows attackers to create or modify delegations with roles they don't own or outside their authorized scope, potentially granting unauthorized administrative access and compromising the entire identity infrastructure.

Technical details

This is an improper privilege management vulnerability in Apache Syncope's delegation functionality. The vulnerable component fails to properly validate that delegations are created/updated only with roles owned by the delegating user and within the same realm subtree for which delegation management authority was granted. The attack requires network access to the Syncope administration interface and likely authenticated access, but allows an authenticated user with delegation privileges to escalate their access to roles and realms beyond their legitimate scope. Successful exploitation enables unauthorized privilege escalation and lateral movement within the identity infrastructure. Patches are available in versions 4.0.8, 4.1.3, and later.

Affected products

  • Apache Syncope 3.0.0-M0 through 3.0.16, 4.0.0-M0 through 4.0.7, 4.1.0-M0 through 4.1.2

Timeline

  • 2026-09-14: disclosed
  • 2026-09-14: patched: Fixed in versions 4.0.8, 4.1.3, and later

References