Improper privilege management in Apache Syncope - CVE-2026-62183
Published: August 24, 2026
Vulnerability details
The vulnerability allows a remote user to escalate privileges.
The vulnerability exists due to improper privilege management in the user self-service REST API when processing self-registration or self-update requests under affected workflow adapter configurations. A remote user can send a crafted REST API call to escalate privileges.
Exploitation is possible when the all-Java user workflow adapter is configured, or when the Flowable user workflow adapter is used with a BPMN definition that does not require admin approval for user self-registration or self-update requests.