Improper Verification of Cryptographic Signature in Apache Syncope - CVE-2026-87802
Published: September 15, 2026
Vulnerability details
The vulnerability allows a remote attacker to gain full access to services proxied by SRA.
The vulnerability exists due to improper verification of cryptographic signatures in SRA OAuth 2.0 JWT signature verification when SRA is configured for OAuth 2.0 without a JWKS set URI assigned. A remote attacker can forge arbitrary JWTs to impersonate any user identity and permissions to gain full access to services proxied by SRA.