CRITICAL 9.8 NVD
CVE-2026-73668
Incorrect Authorization vulnerability in Apache Syncope. An administrator with adequate entitlements in a given Realm may be able to read via REST the full
Incorrect Authorization vulnerability in Apache Syncope.
An administrator with adequate entitlements in a given Realm may be able to read via REST the full Connector configuration, confidential properties included, scoped in another Realm and thus be able to effectively duplicate such Connector instance into the Realm they have administration rights for.
This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 Through 4.0.7, from 4.1.0-M0 through 4.1.2.
Users are recommended to upgrade to version 4.0.8 / 4.1.3, which fix this issue.
References
- https://lists.apache.org/thread/4lgsbbgc72mngf6mc1q5b1cj3d9nyphn
- http://www.openwall.com/lists/oss-security/2026/09/14/11
- https://www.openwall.com/lists/oss-security/2026/09/14/11
This critical severity vulnerability with a CVSS score of 9.8 was published on 2026-09-14 via NVD.
Risk Timeline
CVE Disclosed2026-09-14 · 0 days ago
Remediation Resources
Official Advisory
www.openwall.com/lists/oss-security/2026/09/14/11Official Advisory
www.openwall.com/lists/oss-security/2026/09/14/11Analysis & PoC
lists.apache.org/thread/4lgsbbgc72mngf6mc1q5b1cj3d9nyphn
vulnfeed aggregates 10822 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.