Improper access control in Apache Syncope - CVE-2026-42797
Published: August 25, 2026
Vulnerability details
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to improper access control in JexlContextBuilder when evaluating a crafted JEXL expression for derived schemas. A remote user can create a malicious JEXL expression to disclose sensitive information.
Exploitation requires administrative access with adequate entitlements for Derived Schemas, and the exposed data is limited to user-related security-sensitive information accessible by an administrator with sufficient entitlements for User read.