Insertion of Sensitive Information Into Sent Data in Apache Syncope - CVE-2026-78336

 

Insertion of Sensitive Information Into Sent Data in Apache Syncope - CVE-2026-78336

Published: September 15, 2026


Vulnerability identifier: #VU149993
CSH Severity: Low
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-78336
CWE-ID: CWE-201
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to disclose OIDC client secrets.

The vulnerability exists due to insertion of sensitive information into sent data in the OIDCC4UI provider list when handling requests for configured OIDC providers. A remote user can query the provider list to disclose OIDC client secrets.


Affected software

Apache Syncope

How to mitigate CVE-2026-78336

Install security update from vendor's website.

Apache Syncope - addressed in versions 4.0.8, 4.1.3

External References

Related Security Bulletins