30
30
30
45
30
30
45
30
30
30
30
30
30
45
30
30
45
30
30
30
30
30
30
30
30
30
30
45
30
30
30
CVE-2026-77181: Apache Syncope: ClientApp update entitlement not effective
Apache Syncope discloses low-severity CVE-2026-77181, an incorrect authorization flaw where the ClientApp update entitlement is not effective in versions 3.0.x through 4.1.2.
Francesco Chicchiriccò posted a low-severity advisory for CVE-2026-77181, an Incorrect Authorization vulnerability in Apache Syncope's syncope-core-am-logic module. Affected versions include 3.0.0-M0 through 3.0.16, 4.0.0-M0 through 4.0.7, and 4.1.0-M0 through 4.1.2. An administrator holding the ClientApp update entitlement finds it is not applied as expected. No exploitation is reported and the issue is rated low severity.
10
30
30
30
30
30
30
45
30