CVE-2026-75030: Apache Syncope: Incomplete authorization checks for Group members deprovisioning
Apache Syncope patches missing authorization checks (CVE-2026-75030) in Group members deprovisioning that administrators can abuse.
CVE-2026-75030 is a moderate-severity missing authorization vulnerability in Apache Syncope's Group members deprovisioning logic (syncope-core-idrepo-logic). An administrator with task execution permissions can bypass the incomplete authorization checks. Affected versions include 3.0.0-M0 through 3.0.16, 4.0.0-M0 through 4.0.7, and 4.1.0-M0 through 4.1.2.
- Incomplete authorization checks in Group members deprovisioning
- Rated moderate severity, missing authorization class
- Exploitable by an administrator with task execution permissions
- Affects 3.0.x, 4.0.x, and 4.1.x release lines
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-75030 | Missing Authorization in Apache Syncope Enables Mass Group Member (De)Provisioning Apache Syncope, an open-source identity management system, contains a missing authorization flaw (CWE-862) in which group-level administration checks are not enforced during task execution. An administrator who holds only task execution entitlements can trigger group member provisioning or deprovisioning tasks that add or remove users from groups at scale, even for groups they are not entitled to administer. Successful abuse lets such an attacker grant unauthorized access to connected resources via mass group assignments, or cause widespread and disruptive access revocation across downstream systems. Affected deployments are Apache Syncope 3.0.0-M0 through 3.0.16, 4.0.0-M0 through 4.0.7, and 4.1.0-M0 through 4.1.2. There is currently no evidence of exploitation: no public PoC is known and the CVE is not in the CISA KEV catalog. Do: Upgrade to Apache Syncope 4.0.8 or 4.1.3; note that the 3.0.x line has no fixed release, so 3.0 deployments should migrate directly to a patched 4.x version. Until patched, restrict task execution entitlements to a minimal set of fully trusted administrators. Audit task execution history and group membership changes for any unexpected mass provisioning or deprovisioning of group members. | 9.8 | — |
| nicheLikely hundreds to low thousands of self-hosted enterprise deployments |
Posted by Francesco Chicchiriccò on Sep 14 Severity: moderate Affected versions: - Apache Syncope (org.apache.syncope.core.idrepo:syncope-core-idrepo-logic) 3.0.0-M0 through 3.0.16 - Apache Syncope (org.apache.syncope.core.idrepo:syncope-core-idrepo-logic) 4.0.0-M0 through 4.0.7 - Apache Syncope (org.apache.syncope.core.idrepo:syncope-core-idrepo-logic) 4.1.0-M0 through 4.1.2 Description: Missing Authorization vulnerability in Apache Syncope. An administrator with task execution...
This source does not provide full text. Read it at seclists.org.