Open redirect in Apache Syncope - CVE-2026-73191

 

Open redirect in Apache Syncope - CVE-2026-73191

Published: September 15, 2026


Vulnerability identifier: #VU149979
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-73191
CWE-ID: CWE-601
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to redirect users to an untrusted site.

The vulnerability exists due to improper validation of client-supplied forwarded HTTP headers in the CAS service URL calculation of Syncope SRA when handling forwarded HTTP headers. A remote attacker can supply crafted Forwarded HTTP headers to redirect users to an untrusted site.

The issue occurs when Syncope SRA is configured for CAS authentication.


Affected software

Apache Syncope

How to mitigate CVE-2026-73191

Install security update from vendor's website.

Apache Syncope - addressed in versions 4.0.8, 4.1.3

External References

Related Security Bulletins