Information disclosure in Apache Syncope - CVE-2026-73178
Published: September 15, 2026
Vulnerability details
The vulnerability allows a remote user to impersonate users with higher administration entitlements.
The vulnerability exists due to exposure of sensitive information to an unauthorized actor in the REST access token listing functionality when accessing the list of existing access tokens via REST. A remote privileged user can retrieve signed JWT bodies from existing access tokens to impersonate users with higher administration entitlements.