Incorrect Authorization vulnerability in Apache Syncope.
Delegated administration security checks performed by Reconciliation service's pull and push, being incomplete, could accept calls by administrator not provided with adequate entitlements.
This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 Through 4.0.7, from 4.1.0-M0 through 4.1.2.
Users are recommended to upgrade to version 4.0.8 / 4.1.3, which fix this issue.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-09-14 14:17
Updated : 2026-09-14 20:58
NVD link : CVE-2026-73370
Mitre link : CVE-2026-73370
CVE.ORG link : CVE-2026-73370
JSON object : View
Products Affected
No product.
CWE
CWE-863
Incorrect Authorization
