Incorrect Auth in Apache Syncope 3.x-4.1 REST (CVE-2026-73668)
CVE-2026-73668 Published on September 14, 2026
Apache Syncope: Cross-realm disclosure of confidential ConnId bundles configuration values
Incorrect Authorization vulnerability in Apache Syncope.
An administrator with adequate entitlements in a given Realm may be able to read via REST the full Connector configuration, confidential properties included, scoped in another Realm and thus be able to effectively duplicate such Connector instance into the Realm they have administration rights for.
This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 Through 4.0.7, from 4.1.0-M0 through 4.1.2.
Users are recommended to upgrade to version 4.0.8 / 4.1.3, which fix this issue.
Vulnerability Analysis
CVE-2026-73668 is exploitable with network access, and does not require authorization privileges or user interaction. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to be critical as this vulnerability has a high impact to the confidentiality, integrity and availability of this component.
Weakness Type
What is an AuthZ Vulnerability?
The software performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check. This allows attackers to bypass intended access restrictions.
CVE-2026-73668 has been classified to as an AuthZ vulnerability or weakness.
Products Associated with CVE-2026-73668
Want to know whenever a new CVE is published for Apache Syncope? stack.watch will email you.
Affected Versions
Apache Software Foundation Apache Syncope:- Version 3.0.0-M0, <= 3.0.16 is affected.
- Version 4.0.0-M0, <= 4.0.7 is affected.
- Version 4.1.0-M0, <= 4.1.2 is affected.