Exposure of sensitive information through data queries vulnerability in Apache Syncope.
An administrator with adequate entitlements for Derived Schemas can create a malicious JEXL expression which allows any administrator with sufficient entitlements for User read to access LinkedAccount's (if present) or Manager's (if defined) sensitive information, possibly including hashed credentials.
This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 Through 4.0.7, from 4.1.0-M0 through 4.1.2.
Users are recommended to upgrade to version 4.0.8 / 4.1.3, which fix this issue.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-09-14 13:18
Updated : 2026-09-14 20:58
NVD link : CVE-2026-77883
Mitre link : CVE-2026-77883
CVE.ORG link : CVE-2026-77883
JSON object : View
Products Affected
No product.
CWE
CWE-202
Exposure of Sensitive Information Through Data Queries
