ZeroHour
oss-securitypublished ()ingested 1

CVE-2026-73178: Apache Syncope: JWT Access Token takeover

AI summary · glm-5.3

Apache Syncope discloses CVE-2026-73178, an important-severity flaw enabling JWT access token takeover in versions 3.0.x through 4.1.2.

Apache Syncope disclosed CVE-2026-73178, an Exposure of Sensitive Information to an Unauthorized Actor vulnerability rated important that allows JWT access token takeover. Affected versions include syncope-core-provisioning-java 3.0.0-M0 through 3.0.16, 4.0.0-M0 through 4.0.7, and 4.1.0-M0 through 4.1.2. Users should upgrade to the latest fixed releases.

  • JWT access token takeover via sensitive information exposure to unauthorized actors
  • Affects Syncope 3.0.x, 4.0.x, and 4.1.x branches up to 3.0.16, 4.0.7, and 4.1.2
  • Rated important severity by the Apache Syncope project

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-73178
JWT access token leak enables admin impersonation in Apache Syncope

Apache Syncope, an open-source identity management (IdM) server, exposes sensitive information to an unauthorized actor through its REST API: an administrator with adequate entitlements can retrieve the list of all existing access tokens, including their signed JWT bodies. By replaying one of these stolen JWTs, that administrator can issue further REST requests while impersonating users who hold higher administration entitlements, effectively escalating to full administrative control of the identity deployment. The flaw affects Syncope 3.0.0-M0 through 3.0.16, 4.0.0-M0 through 4.0.7, and 4.1.0-M0 through 4.1.2, and is fixed in 4.0.8 and 4.1.3. No CVSS score has been assigned yet, no public proof-of-concept is known, and there is no evidence of exploitation in the wild.

Do: Upgrade to Apache Syncope 4.0.8 or 4.1.3 as soon as possible — the 3.0.x line has no fixed release, so 3.0.16 users must migrate to a patched 4.x version. After upgrading, revoke and reissue all access tokens and review REST audit logs for any administrative enumeration of the token list or anomalous authenticated requests. Until patched, restrict the entitlements that permit listing access tokens via REST.

7.5
  • Apache Syncope 3.0.0-M0 through 3.0.16
  • Apache Syncope 4.0.0-M0 through 4.0.7
  • Apache Syncope 4.1.0-M0 through 4.1.2
nichelikely hundreds to low thousands of self-hosted enterprise deployments worldwide (order of magnitude ~1,000)
Full article

Posted by Francesco Chicchiriccò on Sep 14 Severity: important Affected versions: - Apache Syncope (org.apache.syncope.core:syncope-core-provisioning-java) 3.0.0-M0 through 3.0.16 - Apache Syncope (org.apache.syncope.core:syncope-core-provisioning-java) 4.0.0-M0 through 4.0.7 - Apache Syncope (org.apache.syncope.core:syncope-core-provisioning-java) 4.1.0-M0 through 4.1.2 Description: Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Syncope. An...

This source does not provide full text. Read it at seclists.org.