Inclusion of Sensitive Information in Log Files in Apache Syncope - CVE-2026-87779
Published: September 15, 2026
Vulnerability details
The vulnerability allows a local user to disclose sensitive information.
The vulnerability exists due to insertion of sensitive information into log files in Apache Syncope AES key handling when an AES key with a non-standard length is configured. A local user can read the logged resulting key value to disclose sensitive information.