Incorrect authorization in Apache Syncope - CVE-2026-77181
Published: September 15, 2026
Vulnerability details
The vulnerability allows a remote user to modify ClientApps without the required update entitlement.
The vulnerability exists due to improper authorization in ClientApp entitlement checks when performing ClientApp update operations. A remote privileged user can use the ClientApp create entitlement to invoke ClientApp update operations to modify ClientApps without the required update entitlement.