Insertion of Sensitive Information Into Sent Data in Apache Syncope - CVE-2026-78336
Published: September 15, 2026
Vulnerability identifier: #VU149993
CSH Severity: Low
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-78336
CWE-ID: CWE-201
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote user to disclose OIDC client secrets.
The vulnerability exists due to insertion of sensitive information into sent data in the OIDCC4UI provider list when handling requests for configured OIDC providers. A remote user can query the provider list to disclose OIDC client secrets.
Affected software
Apache Syncope
How to mitigate CVE-2026-78336
Install security update from vendor's website.
Apache Syncope - addressed in versions 4.0.8, 4.1.3