Open redirect in Apache Syncope - CVE-2026-73191
Published: September 15, 2026
Vulnerability details
The vulnerability allows a remote attacker to redirect users to an untrusted site.
The vulnerability exists due to improper validation of client-supplied forwarded HTTP headers in the CAS service URL calculation of Syncope SRA when handling forwarded HTTP headers. A remote attacker can supply crafted Forwarded HTTP headers to redirect users to an untrusted site.
The issue occurs when Syncope SRA is configured for CAS authentication.