Executive brief
Apache Syncope is an identity management platform used to manage user provisioning and access control across enterprise systems. An administrator in one organizational realm can read confidential connector configuration details belonging to other realms through the REST API, potentially allowing them to duplicate connectors and gain unauthorized access to systems outside their administrative scope.
Technical details
An incorrect authorization vulnerability exists in Apache Syncope's REST API endpoints for accessing Connector configurations. Administrators with entitlements in one Realm can construct REST queries to read the full configuration—including confidential properties—of Connectors scoped to different Realms. The vulnerability stems from insufficient authorization checks on cross-realm Connector resource access. An authenticated administrator can exploit this to view sensitive configuration data and duplicate Connector instances into Realms where they have administrative rights. The vulnerability affects versions 3.0.0-M0 through 3.0.16, 4.0.0-M0 through 4.0.7, and 4.1.0-M0 through 4.1.2. Patches are available in versions 4.0.8 and 4.1.3.
Affected products
- Apache Syncope 3.0.0-M0 through 3.0.16, 4.0.0-M0 through 4.0.7, 4.1.0-M0 through 4.1.2
Timeline
- 2026-09-14: disclosed