CVE-2026-75015: Apache Syncope: Nested secrets leak cleartext into audit records readable
Apache Syncope leaks nested secrets in cleartext into audit records readable by unauthorized users; affects 3.0.x, 4.0.x, and 4.1.x versions.
CVE-2026-75015 is an insufficiently protected credentials vulnerability in Apache Syncope where audit events expose nested secrets in cleartext to users able to read those records. Affected component is syncope-core-provisioning-java 3.0.0-M0 through 3.0.16, 4.0.0-M0 through 4.0.7, and 4.1.0-M0 through 4.1.2. Apache rates the issue moderate severity, and users should upgrade to fixed releases.
- CVE-2026-75015 rated moderate severity
- Nested secrets leak in cleartext into audit records
- Affects syncope-core-provisioning-java 3.0.x, 4.0.x, 4.1.x lines
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-75015 | Insufficiently Masked Secrets in Apache Syncope Audit Events Apache Syncope, an open-source identity management server, fails to properly mask sensitive values (such as nested secrets in cleartext) carried in the payloads of audit events before they are written to the configured audit store. The flaw is triggered during normal operation whenever audited operations include sensitive payload data, which is then persisted in readable form. This allows an administrator, or anyone else with access to the audit store, to view cleartext credentials they are not authorized to see — a privilege-boundary information exposure rather than a remotely exploitable flaw. All supported release lines are affected: 3.0.0-M0 through 3.0.16, 4.0.0-M0 through 4.0.7, and 4.1.0-M0 through 4.1.2. No CVSS score has been assigned yet, and there is no public proof of concept or known in-the-wild exploitation. Do: Upgrade to Apache Syncope 4.1.3, or 4.0.8 if you are on the 4.0 line; no fix is listed for the 3.0.x branch, so those deployments should move to a fixed 4.x release. Because secrets may already have been logged, inspect the configured audit store for cleartext sensitive values, purge or mask those records, and rotate any credentials that were captured. Restrict read access to the audit store to the minimum set of personnel while remediation is underway. | 4.9 | — |
| nichelikely hundreds to low thousands of self-hosted deployments worldwide |
Posted by Francesco Chicchiriccò on Sep 14 Severity: moderate Affected versions: - Apache Syncope (org.apache.syncope.core:syncope-core-provisioning-java) 3.0.0-M0 through 3.0.16 - Apache Syncope (org.apache.syncope.core:syncope-core-provisioning-java) 4.0.0-M0 through 4.0.7 - Apache Syncope (org.apache.syncope.core:syncope-core-provisioning-java) 4.1.0-M0 through 4.1.2 Description: Insufficiently Protected Credentials vulnerability in Apache Syncope. Audit events, when sent to the...
This source does not provide full text. Read it at seclists.org.