Improper Verification of Cryptographic Signature in Apache Syncope - CVE-2026-87802

 

Improper Verification of Cryptographic Signature in Apache Syncope - CVE-2026-87802

Published: September 15, 2026


Vulnerability identifier: #VU149998
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-87802
CWE-ID: CWE-347
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain full access to services proxied by SRA.

The vulnerability exists due to improper verification of cryptographic signatures in SRA OAuth 2.0 JWT signature verification when SRA is configured for OAuth 2.0 without a JWKS set URI assigned. A remote attacker can forge arbitrary JWTs to impersonate any user identity and permissions to gain full access to services proxied by SRA.


Affected software

Apache Syncope

How to mitigate CVE-2026-87802

Install security update from vendor's website.

Apache Syncope - addressed in versions 4.0.8, 4.1.3

External References

Related Security Bulletins