Junglewise Threat Intelligence

CVE-2026-75030: Apache Syncope missing authorization in task execution

CVE-2026-75030 · Severity: critical · CVSS 9.8 · Published 2026-09-14

Vendors: Apache.

Executive brief

Apache Syncope is an identity and access management platform used to provision and manage user accounts and group memberships across enterprise systems. A vulnerability in task execution allows administrators with specific entitlements to bypass authorization checks and mass provision or deprovision group members without proper access controls, potentially exposing organizations to unauthorized changes in their identity systems.

Technical details

This missing authorization vulnerability exists in Apache Syncope's task execution framework. An administrator with task execution entitlements can bypass group-related authorization checks to perform bulk (de)provisioning operations on group members, despite lacking the necessary group administration capabilities. The vulnerability affects versions 3.0.0 through 3.0.16, 4.0.0 through 4.0.7, and 4.1.0 through 4.1.2. The attack requires administrative privileges and authentication to the system. Apache has released fixed versions 4.0.8 and 4.1.3 to address this issue.

Affected products

  • Apache Syncope 3.0.0-M0 through 3.0.16, 4.0.0-M0 through 4.0.7, 4.1.0-M0 through 4.1.2

Timeline

  • 2026-09-14: disclosed

References