Apache Syncope v4.0.7: Unchecked Authorization Enables Mass (De)Provision
CVE-2026-75030 Published on September 14, 2026
Apache Syncope: Incomplete authorization checks for Group members deprovisioning
Missing Authorization vulnerability in Apache Syncope.
An administrator with task execution entitlements might be able to mass (de)provision group members, regardless of their group-related administration capabilities.
This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 Through 4.0.7, from 4.1.0-M0 through 4.1.2.
Users are recommended to upgrade to version 4.0.8 / 4.1.3, which fix this issue.
Vulnerability Analysis
CVE-2026-75030 is exploitable with network access, and does not require authorization privileges or user interaction. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to be critical as this vulnerability has a high impact to the confidentiality, integrity and availability of this component.
Weakness Type
What is an AuthZ Vulnerability?
The software does not perform an authorization check when an actor attempts to access a resource or perform an action.
CVE-2026-75030 has been classified to as an AuthZ vulnerability or weakness.
Products Associated with CVE-2026-75030
Want to know whenever a new CVE is published for Apache Syncope? stack.watch will email you.
Affected Versions
Apache Software Foundation Apache Syncope:- Version 3.0.0-M0, <= 3.0.16 is affected.
- Version 4.0.0-M0, <= 4.0.7 is affected.
- Version 4.1.0-M0, <= 4.1.2 is affected.