Incorrect authorization in Apache Syncope - CVE-2026-73370
Published: September 15, 2026
Vulnerability details
The vulnerability allows a remote user to perform unauthorized reconciliation operations.
The vulnerability exists due to incorrect authorization in the Reconciliation service's pull and push operations when handling requests from delegated administrators. A remote user can invoke reconciliation operations without adequate entitlements to perform unauthorized reconciliation operations.
The incomplete security checks affect cross-realm boundaries.