ZeroHour
oss-securitypublished ()ingested

CVE-2026-73470: Apache Syncope: Delegating users can grant unowned Roles

mediumVulnerabilityimportance 25CVE-2026-73470
AI summary · glm-5.3

Apache Syncope CVE-2026-73470 lets delegated users grant roles they do not own via crafted delegations.

Apache Syncope disclosed CVE-2026-73470, an improper privilege management vulnerability rated important. Delegations can be created or updated so that delegated users are able to grant roles they do not own, breaking ownership constraints. The flaw affects syncope-core-provisioning-java in versions 3.0.0-M0 through 3.0.16, 4.0.0-M0 through 4.0.7, and 4.1.0-M0 through 4.1.2. Users are advised to upgrade to the latest fixed releases.

  • Improper privilege management allows granting unowned Roles via delegations
  • Affects Syncope provisioning module 3.0.x, 4.0.x, and 4.1.x lines
  • Rated important by the Apache Syncope project
  • No exploitation reported; upgrade recommended

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-73470
Privilege escalation via delegation management in Apache Syncope

Apache Syncope, an open-source enterprise identity management (IdM) platform, contains an improper privilege management flaw (CWE-269) in its delegation feature: a user authorized to manage delegations can create or update a delegation that includes Roles the delegating user does not own, or that targets a Realm outside the subtree the delegation authority was granted for. The issue is triggered through normal delegation administration by an authenticated user, and exploitation allows them to confer roles beyond their legitimate entitlements — potentially including administrative roles — to themselves or others, expanding control over managed identities, accounts, and provisioning workflows. Affected deployments are those running Syncope 3.0.0-M0 through 3.0.16, 4.0.0-M0 through 4.0.7, or 4.1.0-M0 through 4.1.2. No public proof of concept exists, there is no evidence of exploitation in the wild, and CVSS has not yet been scored.

Do: Upgrade to Apache Syncope 4.0.8 or 4.1.3; 3.0.x users must move to a patched 4.x release since no 3.0 fix was issued. Until upgraded, audit existing delegations for Roles not owned by the delegating user or outside the granted Realm subtree, and restrict delegation-management rights to a minimal set of trusted administrators. Review historical delegation create/update events in logs for signs of prior abuse.

9.8
  • Apache Syncope 3.0.0-M0 through 3.0.16 (no fixed 3.0.x release; upgrade to a patched 4.x version)
  • Apache Syncope 4.0.0-M0 through 4.0.7 (fixed in 4.0.8)
  • Apache Syncope 4.1.0-M0 through 4.1.2 (fixed in 4.1.3)
nichelikely on the order of hundreds to a few thousand self-hosted enterprise IdM deployments worldwide
Full article

Posted by Francesco Chicchiriccò on Sep 14 Severity: important Affected versions: - Apache Syncope (org.apache.syncope.core:syncope-core-provisioning-java) 3.0.0-M0 through 3.0.16 - Apache Syncope (org.apache.syncope.core:syncope-core-provisioning-java) 4.0.0-M0 through 4.0.7 - Apache Syncope (org.apache.syncope.core:syncope-core-provisioning-java) 4.1.0-M0 through 4.1.2 Description: Improper Privilege Management vulnerability in Apache Syncope. Delegations can be created or updated...

This source does not provide full text. Read it at seclists.org.