ZeroHour

CVE-2026-73470

niche

Privilege escalation via delegation management in Apache Syncope

CVSS 3.1
9.8 critical
EPSS
Published
()
Modified
AI analysis

Apache Syncope, an open-source enterprise identity management (IdM) platform, contains an improper privilege management flaw (CWE-269) in its delegation feature: a user authorized to manage delegations can create or update a delegation that includes Roles the delegating user does not own, or that targets a Realm outside the subtree the delegation authority was granted for. The issue is triggered through normal delegation administration by an authenticated user, and exploitation allows them to confer roles beyond their legitimate entitlements — potentially including administrative roles — to themselves or others, expanding control over managed identities, accounts, and provisioning workflows. Affected deployments are those running Syncope 3.0.0-M0 through 3.0.16, 4.0.0-M0 through 4.0.7, or 4.1.0-M0 through 4.1.2. No public proof of concept exists, there is no evidence of exploitation in the wild, and CVSS has not yet been scored.

What to do: Upgrade to Apache Syncope 4.0.8 or 4.1.3; 3.0.x users must move to a patched 4.x release since no 3.0 fix was issued. Until upgraded, audit existing delegations for Roles not owned by the delegating user or outside the granted Realm subtree, and restrict delegation-management rights to a minimal set of trusted administrators. Review historical delegation create/update events in logs for signs of prior abuse.

Affected
Apache Syncope3.0.0-M0 through 3.0.16 (no fixed 3.0.x release; upgrade to a patched 4.x version)
Apache Syncope4.0.0-M0 through 4.0.7 (fixed in 4.0.8)
Apache Syncope4.1.0-M0 through 4.1.2 (fixed in 4.1.3)
Estimated exposure
nichelikely on the order of hundreds to a few thousand self-hosted enterprise IdM deployments worldwide — Apache Syncope is a self-hosted, on-premises enterprise identity management server with no public active-install telemetry and typically no internet-facing footprint, so the estimate is based on its niche enterprise adoption profile rather…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Improper Privilege Management vulnerability in Apache Syncope. Delegations can be created or updated with Roles not owned by the delegating User, or not for the same Realm subtree under the delegation management was granted for. This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 Through 4.0.7, from 4.1.0-M0 through 4.1.2. Users are recommended to upgrade to version 4.0.8 / 4.1.3, which fix this issue.

Weakness
CWE-269
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

CVE-2026-73470: Apache Syncope: Delegating users can grant unowned Roles

Apache Syncope CVE-2026-73470 lets delegated users grant roles they do not own via crafted delegations.

Apache Syncope disclosed CVE-2026-73470, an improper privilege management vulnerability rated important. Delegations can be created or updated so that delegated users are able to grant roles they do not own, breaking ownership constraints. The flaw affects syncope-core-provisioning-java in versions 3.0.0-M0 through 3.0.16, 4.0.0-M0 through 4.0.7, and 4.1.0-M0 through 4.1.2. Users are advised to upgrade to the latest fixed releases.

oss-security · 1d agoVulnerabilityCVE-2026-73470