CVE-2026-73370: Apache Syncope: Cross-Realm boundaries reconciliation bypass
Incorrect Authorization vulnerability in Apache Syncope.
Delegated administration security checks performed by Reconciliation service's pull and push, being incomplete, could accept calls by administrator not provided with adequate entitlements.
This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 Through 4.0.7, from 4.1.0-M0 through 4.1.2.
Users are recommended to upgrade to version 4.0.8 / 4.1.3, which fix this issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache Syncopeto a version that resolves this vulnerability.Fixed in 4.0.8 - Upgrade
Upgrade
Apache Syncopeto a version that resolves this vulnerability.Fixed in 4.1.3
Event History
Frequently Asked Questions
Which deployments are affected?
Affected releases are Apache Syncope 3.0.0-M0 through 3.0.16, 4.0.0-M0 through 4.0.7, and 4.1.0-M0 through 4.1.2.
What level of access does an attacker need?
Exploitation requires an administrator whose entitlements are insufficient for the requested cross-realm operation. Incomplete delegated-administration checks in Reconciliation pull and push can nevertheless accept that administrator's calls.
Which functionality is involved?
The issue is in the Reconciliation service's pull and push operations, where delegated-administration authorization checks are incomplete.
What is the recommended remediation?
Upgrade Apache Syncope to version 4.0.8 or 4.1.3, which fix the issue.