CVE-2026-77181: Apache Syncope: ClientApp update entitlement not effective
Apache Syncope discloses low-severity CVE-2026-77181, an incorrect authorization flaw where the ClientApp update entitlement is not effective in versions 3.0.x through 4.1.2.
Francesco Chicchiriccò posted a low-severity advisory for CVE-2026-77181, an Incorrect Authorization vulnerability in Apache Syncope's syncope-core-am-logic module. Affected versions include 3.0.0-M0 through 3.0.16, 4.0.0-M0 through 4.0.7, and 4.1.0-M0 through 4.1.2. An administrator holding the ClientApp update entitlement finds it is not applied as expected. No exploitation is reported and the issue is rated low severity.
- CVE-2026-77181 rated low severity, incorrect authorization in Apache Syncope.
- Affects syncope-core-am-logic 3.0.0-M0–3.0.16, 4.0.0-M0–4.0.7, 4.1.0-M0–4.1.2.
- ClientApp update entitlement fails to take effect for administrators.
- No exploitation observed; no PoC mentioned.
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-77181 | Broken entitlement check on ClientApp updates in Apache Syncope Apache Syncope, an open-source identity management and provisioning platform, incorrectly checks authorization for connected application (ClientApp) changes: the CLIENTAPP_UPDATE entitlement is never honored, while the CLIENTAPP_CREATE entitlement is enforced for both create and update operations. The flaw is triggered when an administrator or delegated user calls the ClientApp update operation via the admin console or REST API, causing the wrong entitlement to be evaluated. A user holding only the create entitlement can therefore modify existing ClientApp definitions (such as OIDC/SAML client applications) beyond their intended privileges, while a user holding only the update entitlement is improperly blocked. Affected deployments are Syncope 3.0.0-M0 through 3.0.16, 4.0.0-M0 through 4.0.7, and 4.1.0-M0 through 4.1.2. No public proof of concept exists and no exploitation in the wild has been reported. Do: Upgrade to Apache Syncope 4.0.8 or 4.1.3, which correct the entitlement check; users on the 3.0.x line should migrate to a fixed 4.x release since no 3.0 fix is listed. Until patched, audit which accounts hold the CLIENTAPP_CREATE entitlement and treat them as effectively having ClientApp update rights; review audit logs for unexpected ClientApp modifications by create-only administrators. | 9.8 | — |
| nichelikely hundreds to low thousands of deployments worldwide |
Posted by Francesco Chicchiriccò on Sep 14 Severity: low Affected versions: - Apache Syncope (org.apache.syncope.core.am:syncope-core-am-logic) 3.0.0-M0 through 3.0.16 - Apache Syncope (org.apache.syncope.core.am:syncope-core-am-logic) 4.0.0-M0 through 4.0.7 - Apache Syncope (org.apache.syncope.core.am:syncope-core-am-logic) 4.1.0-M0 through 4.1.2 Description: Incorrect Authorization vulnerability in Apache Syncope. An administrator with ClientApp's update entitlement is unable...
This source does not provide full text. Read it at seclists.org.