ZeroHour
oss-securitypublished ()ingested
Part of a story covered by 3 sources: “Apache Syncope discloses three cross-Realm authorization vulnerabilities: CVE-2026-73236, CVE-2026-73370, and CVE-2026-73668” — merged summary and timeline →

CVE-2026-73370: Apache Syncope: Cross-Realm boundaries reconciliation bypass

mediumVulnerabilityimportance 20CVE-2026-73370
AI summary · glm-5.3

Apache Syncope CVE-2026-73370 allows reconciliation actions to bypass cross-Realm delegated administration boundaries.

Apache Syncope disclosed CVE-2026-73370, an incorrect authorization vulnerability rated moderate. Delegated administration security checks can be bypassed during reconciliation, allowing actions across Realm boundaries. The flaw affects syncope-core-idm-logic in versions 3.0.0-M0 through 3.0.16, 4.0.0-M0 through 4.0.7, and 4.1.0-M0 through 4.1.2. Users should upgrade to the latest fixed releases.

  • Reconciliation bypasses cross-Realm delegated administration security checks
  • Affects Syncope IDM logic module across 3.0.x, 4.0.x, 4.1.x versions
  • Rated moderate by the Apache Syncope project

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-73370
Broken Authorization in Apache Syncope Reconciliation Bypasses Delegated-Admin Entitlements

Apache Syncope, an open-source identity management (IdM) platform, contains an incorrect authorization flaw (CWE-863) in the Reconciliation service: the delegated-administration security checks applied to its pull and push operations are incomplete. As a result, an administrator account that was never granted the required entitlements can still invoke reconciliation pull and push actions, which synchronize identities across realms and connected resources — enabling reconciliation to be triggered across realm boundaries beyond that admin's delegated scope. This can let an under-privileged or rogue delegated administrator read or alter identity data (users, groups, accounts on connected systems) outside the realm they administer. Affected versions are 3.0.0-M0 through 3.0.16, 4.0.0-M0 through 4.0.7, and 4.1.0-M0 through 4.1.2; fixes are available in 4.0.8 and 4.1.3, with no fixed 3.0.x release listed. The issue has no CVSS score yet, is not in the CISA KEV catalog, and there is no known public PoC or evidence of in-the-wild exploitation.

Do: Upgrade immediately to Apache Syncope 4.0.8 or 4.1.3; organizations still on the 3.0.x line must upgrade to a fixed 4.x release since no 3.0 fix was published. Restrict access to the Reconciliation service (pull/push) so only fully entitled administrators can invoke it, and audit logs for pull/push executions initiated by delegated administrators who lacked the corresponding entitlements. Investigate any resulting cross-realm identity changes or unexpected synchronizations to connected resources.

9.8
  • Apache Syncope
nicheunknown exact count; plausibly hundreds to low thousands of self-hosted enterprise IdM deployments
Full article

Posted by Francesco Chicchiriccò on Sep 14 Severity: moderate Affected versions: - Apache Syncope (org.apache.syncope.core.idm:syncope-core-idm-logic) 3.0.0-M0 through 3.0.16 - Apache Syncope (org.apache.syncope.core.idm:syncope-core-idm-logic) 4.0.0-M0 through 4.0.7 - Apache Syncope (org.apache.syncope.core.idm:syncope-core-idm-logic) 4.1.0-M0 through 4.1.2 Description: Incorrect Authorization vulnerability in Apache Syncope. Delegated administration security checks performed by...

This source does not provide full text. Read it at seclists.org.