oss-security·12d agoCVE-2026-87802: Apache Syncope: SRA OAuth2 JWT signature verification bypass#apache#cve-2026-87802#jwtCVE-2026-878021
oss-security·12d agoCVE-2026-86460: Apache Syncope: Cypher Injection via FIQL Search on Neo4j Persistence#apache#cve-2026-86460#cypher-injectionCVE-2026-864601
oss-security·12d agoCVE-2026-82232: Apache Syncope: SQL injection via sort parameter in Task search#apache#cve-2026-82232#jpaCVE-2026-82232
oss-security·12d agoCVE-2026-78336: Apache Syncope: OIDCC4UI provider list discloses client secrets to any authenticated user#apache#cve-2026-78336#oidcCVE-2026-783361
oss-security·12d agoCVE-2026-78330: Apache Syncope: Privilege escalation for admin user via JWT authentication#apache#cve-2026-78330#jwksCVE-2026-78330
oss-security·12d agoCVE-2026-78318: Apache Syncope: Unauthenticated reflected XSS in Console and Enduser#apache#console#cve-2026-78318CVE-2026-783181
oss-security·12d agoCVE-2026-77883: Apache Syncope: Information disclosure via one-hop JEXL navigation past the JexlContextBuilder name denylist#apache#cve-2026-77883#information-disclosureCVE-2026-778832
oss-security·12d agoCVE-2026-77181: Apache Syncope: ClientApp update entitlement not effective#access-control#apache#authorizationCVE-2026-77181
oss-security·12d agoCVE-2026-75015: Apache Syncope: Nested secrets leak cleartext into audit records readable#apache#audit-records#credential-leakCVE-2026-750151
oss-security·12d agoCVE-2026-73668: Apache Syncope: Cross-realm disclosure of confidential ConnId bundles configuration values#apache#authorization-bypass#connidCVE-2026-73668
oss-security·12d agoCVE-2026-73579: Apache Syncope: Non-recursive Any search could skip Realms restrictions#apache#authorization-bypass#cve-2026-73579CVE-2026-735791
oss-security·12d agoCVE-2026-73470: Apache Syncope: Delegating users can grant unowned Roles#apache#authorization#cve-2026-73470CVE-2026-73470
oss-security·12d agoCVE-2026-73236: Apache Syncope: Cross-Realm authorization bypass in delegated administration#apache#authorization-bypass#cve-2026-73236CVE-2026-73236 2 sources1
oss-security·12d agoCVE-2026-73195: Apache Syncope: CSV export spreadsheet formula injection#apache#csv-injection#cve-2026-73195CVE-2026-731952
oss-security·12d agoCVE-2026-73191: Apache Syncope: CAS service URL injection via Forwarded HTTP headers#apache#cas#cve-2026-73191CVE-2026-73191
oss-security·12d ago highCVE-2026-73178: Apache Syncope: JWT Access Token takeover#apache#cve#identity-managementCVE-2026-731781