ZeroHour
oss-securitypublished ()ingested
Part of a story covered by 3 sources: “Apache Syncope discloses three cross-Realm authorization vulnerabilities: CVE-2026-73236, CVE-2026-73370, and CVE-2026-73668” — merged summary and timeline →

CVE-2026-73668: Apache Syncope: Cross-realm disclosure of confidential ConnId bundles configuration values

mediumVulnerabilityimportance 18CVE-2026-73668
AI summary · glm-5.3

Apache Syncope cross-realm authorization flaw lets administrators read confidential ConnId bundle configuration values from realms they should not access (CVE-2026-73668).

CVE-2026-73668 is an incorrect authorization vulnerability in Apache Syncope allowing an administrator with entitlements in one realm to view confidential ConnId bundle configuration values belonging to other realms. Affected component is syncope-core-idm-logic 3.0.0-M0 through 3.0.16, 4.0.0-M0 through 4.0.7, and 4.1.0-M0 through 4.1.2. Apache rates the issue moderate severity.

  • CVE-2026-73668 rated moderate severity
  • Cross-realm disclosure of ConnId bundle configuration values
  • Affects syncope-core-idm-logic 3.0.x, 4.0.x, 4.1.x lines

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-73668
Cross-Realm Confidential Connector Config Disclosure in Apache Syncope

Apache Syncope, an open-source identity and access management (IdM) platform, contains an incorrect authorization flaw (CWE-863) in its REST API that lets an authenticated administrator who has full entitlements in one Realm read the complete Connector configuration scoped to a different Realm — including confidential properties such as the credentials used to bind to connected external resources (e.g., LDAP/AD, databases) via ConnId connector bundles. The attacker gains those secrets and can effectively clone the Connector instance into their own Realm, giving them working credentials for the target Realm's backend systems and enabling lateral movement outside their delegated administrative scope. The issue affects Syncope 3.0.0-M0 through 3.0.16, 4.0.0-M0 through 4.0.7, and 4.1.0-M0 through 4.1.2; it is fixed in 4.0.8 and 4.1.3 (the 3.0.x line has no listed fix, so those users must upgrade to a fixed 4.x release). Exploitation requires an already-privileged internal account, so the risk is primarily privilege escalation across realm boundaries by semi-trusted or compromised tenant administrators. No CVSS score has been assigned, it is not in the CISA KEV catalog, and no public proof of concept or known in-the-wild exploitation exists.

Do: Upgrade Apache Syncope to 4.0.8 or 4.1.3; deployments still on the 3.0.x line (up to 3.0.16) have no fixed 3.0.x release and should migrate to a fixed 4.x version. Until patched, minimize the number of realm-scoped administrators, review REST access logs for any admin reading Connector configurations outside their own Realm, and rotate the credentials stored in Connector confidential properties (e.g., LDAP/AD and database bind accounts) since they may have been readable cross-realm.

9.8
  • Apache Syncope 3.0.0-M0 through 3.0.16
  • Apache Syncope 4.0.0-M0 through 4.0.7
  • Apache Syncope 4.1.0-M0 through 4.1.2
nicheunknown exact count; likely low thousands of self-hosted enterprise instances at most
Full article

Posted by Francesco Chicchiriccò on Sep 14 Severity: moderate Affected versions: - Apache Syncope (org.apache.syncope.core.idm:syncope-core-idm-logic) 3.0.0-M0 through 3.0.16 - Apache Syncope (org.apache.syncope.core.idm:syncope-core-idm-logic) 4.0.0-M0 through 4.0.7 - Apache Syncope (org.apache.syncope.core.idm:syncope-core-idm-logic) 4.1.0-M0 through 4.1.2 Description: Incorrect Authorization vulnerability in Apache Syncope. An administrator with adequate entitlements in a given...

This source does not provide full text. Read it at seclists.org.