CVE-2026-75015: Apache Syncope: Nested secrets leak cleartext into audit records readable
Insufficiently Protected Credentials vulnerability in Apache Syncope.
Audit events, when sent to the configured store, are not sufficiently masked for the sensitive values they might carry on their payloads, thus allowing administrators to access such sensitive values.
This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 Through 4.0.7, from 4.1.0-M0 through 4.1.2.
Users are recommended to upgrade to version 4.0.8 / 4.1.3, which fix this issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache Syncopeto a version that resolves this vulnerability.Fixed in 4.0.8 - Upgrade
Upgrade
Apache Syncopeto a version that resolves this vulnerability.Fixed in 4.1.3
Event History
Frequently Asked Questions
Who can access the exposed sensitive values?
Administrators who can read audit events in the configured audit store may be able to access sensitive values carried in audit event payloads.
Which deployments are affected?
Affected versions are 3.0.0-M0 through 3.0.16, 4.0.0-M0 through 4.0.7, and 4.1.0-M0 through 4.1.2. The issue concerns audit events that are sent to a configured store.
How can I determine whether my instance is exposed?
Check whether the Syncope version falls within an affected range and whether audit events are being sent to a configured store. If both apply, administrators able to read that store may be able to view unmasked sensitive payload values.
What versions address the issue?
Upgrade to Syncope 4.0.8 or 4.1.3, which fix the issue.