Executive brief
Apache Syncope is an identity and access management platform used to provision and manage user accounts and group memberships across enterprise systems. A vulnerability in task execution allows administrators with specific entitlements to bypass authorization checks and mass provision or deprovision group members without proper access controls, potentially exposing organizations to unauthorized changes in their identity systems.
Technical details
This missing authorization vulnerability exists in Apache Syncope's task execution framework. An administrator with task execution entitlements can bypass group-related authorization checks to perform bulk (de)provisioning operations on group members, despite lacking the necessary group administration capabilities. The vulnerability affects versions 3.0.0 through 3.0.16, 4.0.0 through 4.0.7, and 4.1.0 through 4.1.2. The attack requires administrative privileges and authentication to the system. Apache has released fixed versions 4.0.8 and 4.1.3 to address this issue.
Affected products
- Apache Syncope 3.0.0-M0 through 3.0.16, 4.0.0-M0 through 4.0.7, 4.1.0-M0 through 4.1.2
Timeline
- 2026-09-14: disclosed