CVE-2026-73470: Apache Syncope: Delegating users can grant unowned Roles
Improper Privilege Management vulnerability in Apache Syncope.
Delegations can be created or updated with Roles not owned by the delegating User, or not for the same Realm subtree under the delegation management was granted for.
This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 Through 4.0.7, from 4.1.0-M0 through 4.1.2.
Users are recommended to upgrade to version 4.0.8 / 4.1.3, which fix this issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache Syncopeto a version that resolves this vulnerability.Fixed in 4.0.8 - Upgrade
Upgrade
Apache Syncopeto a version that resolves this vulnerability.Fixed in 4.1.3
Event History
Frequently Asked Questions
Who can exploit this issue?
A user who can create or update delegations is exposed to this flaw. The issue allows delegations to include Roles the delegating user does not own, or Roles outside the Realm subtree for which delegation management was granted.
Which Apache Syncope versions need remediation?
Affected releases are 3.0.0-M0 through 3.0.16, 4.0.0-M0 through 4.0.7, and 4.1.0-M0 through 4.1.2. Upgrade to 4.0.8 or 4.1.3.
What should be reviewed if an upgrade cannot be applied immediately?
Review existing delegations created or updated by users with delegation-management permissions. Identify delegations containing Roles not owned by the delegating user or Roles outside the authorized Realm subtree, and remove or correct them.