CRITICAL 9.8 NVD
CVE-2026-77181
Incorrect Authorization vulnerability in Apache Syncope. An administrator with ClientApp's update entitlement is unable to perform the related operation, whi
Incorrect Authorization vulnerability in Apache Syncope.
An administrator with ClientApp's update entitlement is unable to perform the related operation, while ClientApp's create entitlement is checked both for create and update operations on ClientApp.
This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 Through 4.0.7, from 4.1.0-M0 through 4.1.2.
Users are recommended to upgrade to version 4.0.8 / 4.1.3, which fix this issue.
References
- https://lists.apache.org/thread/swqj31jhbz7hmmkjy42461zp9rhh9lwy
- http://www.openwall.com/lists/oss-security/2026/09/14/16
- https://www.openwall.com/lists/oss-security/2026/09/14/16
This critical severity vulnerability with a CVSS score of 9.8 was published on 2026-09-14 via NVD.
Risk Timeline
CVE Disclosed2026-09-14 · 0 days ago
Remediation Resources
Official Advisory
www.openwall.com/lists/oss-security/2026/09/14/16Official Advisory
www.openwall.com/lists/oss-security/2026/09/14/16Analysis & PoC
lists.apache.org/thread/swqj31jhbz7hmmkjy42461zp9rhh9lwy
vulnfeed aggregates 10822 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.