Improper access control in Synapse - #VU139985
Published: July 29, 2026
Synapse
Detailed vulnerability description
The vulnerability allows a remote attacker to access unintended endpoints.
The vulnerability exists due to improper access control in some Synapse endpoints when processing URLs with extraneous trailing path data behind a reverse proxy that normalizes paths for routing. A remote attacker can send a specially crafted request to access unintended endpoints.
This issue can bypass reverse proxy rules and expose sensitive endpoints, but use of those endpoints may still require a valid access token.