Improper privilege management in Apache Syncope - CVE-2026-73470
Published: September 15, 2026
Vulnerability details
The vulnerability allows a remote user to grant roles they do not own.
The vulnerability exists due to improper privilege management in delegation management when creating or updating delegations. A remote user can create or update a delegation with roles they do not own or roles outside the authorized realm subtree to grant roles they do not own.