Apache Syncope
Apache Software Foundation- Product type
- Other
- Catalog vulnerabilities
- 40
Severity across 40 analyzed records
en
Severity across 40 analyzed records
Verify to analyze this security profile
As of 09/29/2026, within CyStack's analyzed data, Apache Syncope has 28 security vulnerabilities published in the last 90 days. Of these, 23 are rated High or Critical. None of these vulnerabilities is listed in the CISA KEV catalog. CyStack recommends that organizations and individual users remediate applicable vulnerabilities as soon as possible.
CyStack does not yet have sufficient official-source data to identify the latest version of Apache Syncope and determine which vulnerabilities affect that version.
| Vulnerability | Exploitation status | Fix | Published | Severity |
|---|---|---|---|---|
CVE-2026-73191Apache Syncope: CAS service URL injection via Forwarded HTTP headers | Exploitation statusNot known exploited | FixYes | Published09/14/2026 | SeverityMedium |
CVE-2026-73195Apache Syncope: CSV export spreadsheet formula injection | Exploitation statusNot known exploited | FixYes | Published09/14/2026 | SeverityHigh |
CVE-2026-73236Apache Syncope: Cross-Realm authorization bypass in delegated administration | Exploitation statusNot known exploited | FixYes | Published09/14/2026 | SeverityHigh |
CVE-2026-73370Apache Syncope: Cross-Realm boundaries reconciliation bypass | Exploitation statusNot known exploited | FixYes | Published09/14/2026 | SeverityCritical |
CVE-2026-73178Apache Syncope: JWT Access Token takeover | Exploitation statusNot known exploited | FixYes | Published09/14/2026 | SeverityHigh |
CVE-2026-73470Apache Syncope: Delegating users can grant unowned Roles | Exploitation statusNot known exploited | FixYes | Published09/14/2026 | SeverityCritical |
CVE-2026-73579Apache Syncope: Non-recursive Any search could skip Realms restrictions | Exploitation statusNot known exploited | FixYes | Published09/14/2026 | SeverityCritical |
CVE-2026-75015Apache Syncope: Nested secrets leak cleartext into audit records readable | Exploitation statusNot known exploited | FixYes | Published09/14/2026 | SeverityMedium |
CVE-2026-75030Apache Syncope: Incomplete authorization checks for Group members deprovisioning | Exploitation statusNot known exploited | FixYes | Published09/14/2026 | SeverityCritical |
CVE-2026-77051Apache Syncope: SQL injection via unsanitized entityKey and opEvent in Audit Events search | Exploitation statusNot known exploited | FixYes | Published09/14/2026 | SeverityCritical |
CVE-2026-73668Apache Syncope: Cross-realm disclosure of confidential ConnId bundles configuration values | Exploitation statusNot known exploited | FixYes | Published09/14/2026 | SeverityCritical |
CVE-2026-77147Apache Syncope: Groovy Sandbox escape for empty CommandArgs | Exploitation statusNot known exploited | FixYes | Published09/14/2026 | SeverityMedium |
CVE-2026-77181Apache Syncope: ClientApp update entitlement not effective | Exploitation statusNot known exploited | FixYes | Published09/14/2026 | SeverityCritical |
CVE-2026-77883Apache Syncope: Information disclosure via one-hop JEXL navigation past the JexlContextBuilder name denylist | Exploitation statusNot known exploited | FixYes | Published09/14/2026 | SeverityMedium |
CVE-2026-78318Apache Syncope: Unauthenticated reflected XSS in Console and Enduser | Exploitation statusNot known exploited | FixYes | Published09/14/2026 | SeverityMedium |
CVE-2026-78330Apache Syncope: Privilege escalation for admin user via JWT authentication | Exploitation statusNot known exploited | FixYes | Published09/14/2026 | SeverityCritical |
CVE-2026-78336Apache Syncope: OIDCC4UI provider list discloses client secrets to any authenticated user | Exploitation statusNot known exploited | FixYes | Published09/14/2026 | SeverityHigh |
CVE-2026-82232Apache Syncope: SQL injection via sort parameter in Task search | Exploitation statusNot known exploited | FixYes | Published09/14/2026 | SeverityCritical |
CVE-2026-86460Apache Syncope: Cypher Injection via FIQL Search on Neo4j Persistence | Exploitation statusNot known exploited | FixYes | Published09/14/2026 | SeverityCritical |
CVE-2026-87779Apache Syncope: AES Secret Key disclosure via log output | Exploitation statusNot known exploited | FixYes | Published09/14/2026 | SeverityHigh |
CVE-2026-87785Apache Syncope: JWT subject spoofing | Exploitation statusNot known exploited | FixYes | Published09/14/2026 | SeverityCritical |
CVE-2026-87802Apache Syncope: SRA OAuth2 JWT signature verification bypass | Exploitation statusNot known exploited | FixYes | Published09/14/2026 | SeverityCritical |
CVE-2026-62418Apache Syncope: Low-privileged authenticated SSRF in Connectors and Resources check | Exploitation statusNot known exploited | FixYes | Published07/20/2026 | SeverityHigh |
CVE-2026-62183Apache Syncope: User self-service privilege escalation | Exploitation statusNot known exploited | FixYes | Published07/20/2026 | SeverityCritical |
CVE-2026-57308Apache Syncope: SQL injection vulnerability in Audit Events search | Exploitation statusNot known exploited | FixYes | Published07/20/2026 | SeverityCritical |
CVE-2026-53421Apache Syncope: Remote Code Execution via Scripted Connector | Exploitation statusNot known exploited | FixYes | Published07/20/2026 | SeverityCritical |
CVE-2026-53405Apache Syncope: Remote Code Execution via Flowable BPMN Groovy ScriptTask | Exploitation statusNot known exploited | FixYes | Published07/20/2026 | SeverityCritical |
CVE-2026-63071Apache Syncope: RCE via Groovy Sandbox bypass | Exploitation statusNot known exploited | FixYes | Published07/20/2026 | SeverityCritical |
CVE-2026-42797Apache Syncope: JexlContextBuilder Information Disclosure | Exploitation statusNot known exploited | FixYes | Published05/25/2026 | SeverityMedium |
CVE-2026-42782Apache Syncope: Post-auth RCE via Groovy static | Exploitation statusNot known exploited | FixYes | Published05/25/2026 | SeverityHigh |
CVE-2026-23794Apache Syncope: Reflected XSS on Enduser Login | Exploitation statusNot known exploited | FixYes | Published02/03/2026 | SeverityMedium |
CVE-2026-23795Apache Syncope: Console XXE on Keymaster parameters | Exploitation statusNot known exploited | FixYes | Published02/03/2026 | SeverityMedium |
CVE-2025-65998Apache Syncope: Default AES key used for internal password encryption | Exploitation statusNot known exploited | FixYes | Published11/24/2025 | SeverityHigh |
CVE-2025-57738Apache Syncope: Remote Code Execution by delegated administrators | Exploitation statusNot known exploited | FixYes | Published10/20/2025 | SeverityHigh |
CVE-2024-45031Apache Syncope: Stored XSS in Console and Enduser | Exploitation statusNot known exploited | FixYes | Published10/24/2024 | SeverityMedium |
CVE-2024-38503Apache Syncope: HTML tags can be injected into Console or Enduser text fields | Exploitation statusNot known exploited | FixYes | Published07/22/2024 | SeverityLow |
CVE-2018-17186 | Exploitation statusNot confirmed | FixNot confirmed | Published11/06/2018 | SeverityUnknown |
CVE-2018-17184 | Exploitation statusNot confirmed | FixNot confirmed | Published11/06/2018 | SeverityUnknown |
CVE-2018-1322 | Exploitation statusPublic exploit | FixNot confirmed | Published03/20/2018 | SeverityUnknown |
CVE-2018-1321 | Exploitation statusPublic exploit | FixNot confirmed | Published03/20/2018 | SeverityUnknown |
CyStack VulnScan continuously discovers assets, validates vulnerabilities, and helps security teams prioritize remediation across the organization.
Explore CyStack VulnScan