Improper privilege management in Apache Syncope - CVE-2026-78330

 

Improper privilege management in Apache Syncope - CVE-2026-78330

Published: September 15, 2026


Vulnerability identifier: #VU149992
CSH Severity: Low
CVSS v4: 7.7 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-78330
CWE-ID: CWE-269
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to escalate privileges to administrator privileges.

The vulnerability exists due to incorrect privilege assignment in internal JWT authentication when configured JWKS settings, including at least the protocol and key, are disclosed. A remote user can use a valid low-privilege JWT after successful authentication to obtain administrator privileges.


Affected software

Apache Syncope

How to mitigate CVE-2026-78330

Install security update from vendor's website.

Apache Syncope - addressed in versions 4.0.8, 4.1.3

External References

Related Security Bulletins