CVE-2026-73668: Apache Syncope: Cross-realm disclosure of confidential ConnId bundles configuration values
Apache Syncope cross-realm authorization flaw lets administrators read confidential ConnId bundle configuration values from realms they should not access (CVE-2026-73668).
CVE-2026-73668 is an incorrect authorization vulnerability in Apache Syncope allowing an administrator with entitlements in one realm to view confidential ConnId bundle configuration values belonging to other realms. Affected component is syncope-core-idm-logic 3.0.0-M0 through 3.0.16, 4.0.0-M0 through 4.0.7, and 4.1.0-M0 through 4.1.2. Apache rates the issue moderate severity.
18