Insufficiently protected credentials in Apache Syncope - CVE-2026-75015
Published: September 15, 2026
Vulnerability details
The vulnerability allows a local privileged user to disclose sensitive information.
The vulnerability exists due to insufficiently protected credentials in audit event payload masking when accessing audit events in the configured store. A local privileged user can read audit records containing sensitive values to disclose sensitive information.