CVE-2026-73668: Apache Syncope: Cross-realm disclosure of confidential ConnId bundles configuration values
Incorrect Authorization vulnerability in Apache Syncope.
An administrator with adequate entitlements in a given Realm may be able to read via REST the full Connector configuration, confidential properties included, scoped in another Realm and thus be able to effectively duplicate such Connector instance into the Realm they have administration rights for.
This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 Through 4.0.7, from 4.1.0-M0 through 4.1.2.
Users are recommended to upgrade to version 4.0.8 / 4.1.3, which fix this issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 4.0.8 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 4.1.3
Event History
Frequently Asked Questions
Who can exploit this issue?
An administrator who has adequate entitlements in one Realm can exploit the issue to access connector configuration data scoped to another Realm. The issue is therefore relevant where Realm administrators should be isolated from connectors managed in other Realms.
What information could be exposed?
The affected REST access can disclose the full Connector configuration, including confidential properties. An administrator could use the disclosed configuration to effectively duplicate the connector instance in a Realm they administer.
Which Apache Syncope releases are affected and what versions fix it?
Affected releases are 3.0.0-M0 through 3.0.16, 4.0.0-M0 through 4.0.7, and 4.1.0-M0 through 4.1.2. Upgrade to 4.0.8 or 4.1.3 to fix the issue.