MEDIUM 6.1 NVD
CVE-2026-73191
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Apache Syncope. When the Syncope SRA is configured for CAS authentication, the target
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Apache Syncope.
When the Syncope SRA is configured for CAS authentication, the target Apereo CAS instance's URL is calculated by unconditionally looking at client-supplied forwarded HTTP headers.
This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 Through 4.0.7, from 4.1.0-M0 through 4.1.2.
Users are recommended to upgrade to version 4.0.8 / 4.1.3, which fix this issue.
References
- https://lists.apache.org/thread/vx9bons1znhdkdpsxwjpy6qqqjc8xqtk
- http://www.openwall.com/lists/oss-security/2026/09/14/5
- https://www.openwall.com/lists/oss-security/2026/09/14/5
This medium severity vulnerability with a CVSS score of 6.1 was published on 2026-09-14 via NVD.
vulnfeed aggregates 10822 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.