ZeroHour

CVE-2026-75015

niche

Insufficiently Masked Secrets in Apache Syncope Audit Events

CVSS 3.1
4.9 medium
EPSS
Published
()
Modified
AI analysis

Apache Syncope, an open-source identity management server, fails to properly mask sensitive values (such as nested secrets in cleartext) carried in the payloads of audit events before they are written to the configured audit store. The flaw is triggered during normal operation whenever audited operations include sensitive payload data, which is then persisted in readable form. This allows an administrator, or anyone else with access to the audit store, to view cleartext credentials they are not authorized to see — a privilege-boundary information exposure rather than a remotely exploitable flaw. All supported release lines are affected: 3.0.0-M0 through 3.0.16, 4.0.0-M0 through 4.0.7, and 4.1.0-M0 through 4.1.2. No CVSS score has been assigned yet, and there is no public proof of concept or known in-the-wild exploitation.

What to do: Upgrade to Apache Syncope 4.1.3, or 4.0.8 if you are on the 4.0 line; no fix is listed for the 3.0.x branch, so those deployments should move to a fixed 4.x release. Because secrets may already have been logged, inspect the configured audit store for cleartext sensitive values, purge or mask those records, and rotate any credentials that were captured. Restrict read access to the audit store to the minimum set of personnel while remediation is underway.

Affected
Apache Syncope3.0.0-M0 through 3.0.16
Apache Syncope4.0.0-M0 through 4.0.7
Apache Syncope4.1.0-M0 through 4.1.2
Estimated exposure
nichelikely hundreds to low thousands of self-hosted deployments worldwide — Apache Syncope is an enterprise, self-hosted identity-management server with no public install telemetry, and instances are typically deployed inside the corporate network rather than internet-exposed, so exposure is limited to…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Insufficiently Protected Credentials vulnerability in Apache Syncope. Audit events, when sent to the configured store, are not sufficiently masked for the sensitive values they might carry on their payloads, thus allowing administrators to access such sensitive values. This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 Through 4.0.7, from 4.1.0-M0 through 4.1.2. Users are recommended to upgrade to version 4.0.8 / 4.1.3, which fix this issue.

Weakness
CWE-522
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N

In the news

CVE-2026-75015: Apache Syncope: Nested secrets leak cleartext into audit records readable

Apache Syncope leaks nested secrets in cleartext into audit records readable by unauthorized users; affects 3.0.x, 4.0.x, and 4.1.x versions.

CVE-2026-75015 is an insufficiently protected credentials vulnerability in Apache Syncope where audit events expose nested secrets in cleartext to users able to read those records. Affected component is syncope-core-provisioning-java 3.0.0-M0 through 3.0.16, 4.0.0-M0 through 4.0.7, and 4.1.0-M0 through 4.1.2. Apache rates the issue moderate severity, and users should upgrade to fixed releases.

oss-security · 1d agoVulnerabilityCVE-2026-75015