CVE-2026-73370: Apache Syncope: Cross-Realm boundaries reconciliation bypass
Apache Syncope CVE-2026-73370 allows reconciliation actions to bypass cross-Realm delegated administration boundaries.
Apache Syncope disclosed CVE-2026-73370, an incorrect authorization vulnerability rated moderate. Delegated administration security checks can be bypassed during reconciliation, allowing actions across Realm boundaries. The flaw affects syncope-core-idm-logic in versions 3.0.0-M0 through 3.0.16, 4.0.0-M0 through 4.0.7, and 4.1.0-M0 through 4.1.2. Users should upgrade to the latest fixed releases.