Incorrect authorization in Apache Syncope - CVE-2026-73579
Published: September 15, 2026
Vulnerability details
The vulnerability allows a remote user to disclose information outside their authorized realms.
The vulnerability exists due to improper authorization in the Realms filter for non-recursive Any searches when transforming non-recursive Any search requests into backend queries. A remote user can submit a non-recursive Any search request to disclose information outside their authorized realms.