Incorrect authorization in Apache Syncope - CVE-2026-73236
Published: September 15, 2026
Vulnerability details
The vulnerability allows a remote user to bypass cross-realm authorization restrictions.
The vulnerability exists due to incorrect authorization in delegated administration realm hierarchy security checks when handling delegated administration requests for sibling realms whose names begin with the same string. A remote user can exploit prefix matching to bypass cross-realm authorization restrictions.