Incomplete List of Disallowed Inputs in Apache Syncope - CVE-2026-77883
Published: September 15, 2026
Vulnerability details
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to an incomplete denylist in the JexlContextBuilder when processing derived schema JEXL expressions. A remote privileged user can create a malicious JEXL expression to access sensitive LinkedAccount or Manager information.
The disclosed information can include hashed credentials.