CRITICAL 9.8 NVD
CVE-2026-73370
Incorrect Authorization vulnerability in Apache Syncope. Delegated administration security checks performed by Reconciliation service's pull and push, being
Incorrect Authorization vulnerability in Apache Syncope.
Delegated administration security checks performed by Reconciliation service's pull and push, being incomplete, could accept calls by administrator not provided with adequate entitlements.
This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 Through 4.0.7, from 4.1.0-M0 through 4.1.2.
Users are recommended to upgrade to version 4.0.8 / 4.1.3, which fix this issue.
References
- https://lists.apache.org/thread/prv0k3mvorzhngdw405sgb87ckw105gz
- http://www.openwall.com/lists/oss-security/2026/09/14/8
- https://www.openwall.com/lists/oss-security/2026/09/14/8
This critical severity vulnerability with a CVSS score of 9.8 was published on 2026-09-14 via NVD.
Risk Timeline
CVE Disclosed2026-09-14 · 0 days ago
Remediation Resources
Official Advisory
www.openwall.com/lists/oss-security/2026/09/14/8Official Advisory
www.openwall.com/lists/oss-security/2026/09/14/8Analysis & PoC
lists.apache.org/thread/prv0k3mvorzhngdw405sgb87ckw105gz
vulnfeed aggregates 10822 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.