Improper privilege management in Apache Syncope - CVE-2026-78330
Published: September 15, 2026
Vulnerability details
The vulnerability allows a remote user to escalate privileges to administrator privileges.
The vulnerability exists due to incorrect privilege assignment in internal JWT authentication when configured JWKS settings, including at least the protocol and key, are disclosed. A remote user can use a valid low-privilege JWT after successful authentication to obtain administrator privileges.