CVE-2026-75030: Apache Syncope: Incomplete authorization checks for Group members deprovisioning
Missing Authorization vulnerability in Apache Syncope.
An administrator with task execution entitlements might be able to mass (de)provision group members, regardless of their group-related administration capabilities.
This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 Through 4.0.7, from 4.1.0-M0 through 4.1.2.
Users are recommended to upgrade to version 4.0.8 / 4.1.3, which fix this issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache Syncopeto a version that resolves this vulnerability.Fixed in 4.0.8 - Upgrade
Upgrade
Apache Syncopeto a version that resolves this vulnerability.Fixed in 4.1.3
Event History
Frequently Asked Questions
Which deployments are affected?
Apache Syncope versions from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 through 4.0.7, and from 4.1.0-M0 through 4.1.2 are affected.
What level of access does an attacker need?
The attacker must be an administrator with task execution entitlements. They may be able to mass provision or deprovision group members even without the relevant group-administration capabilities.
What should affected users do?
Upgrade to Apache Syncope 4.0.8 or 4.1.3, which fix the issue.