CVE-2026-77883: Apache Syncope: Information disclosure via one-hop JEXL navigation past the JexlContextBuilder name denylist
Exposure of sensitive information through data queries vulnerability in Apache Syncope.
An administrator with adequate entitlements for Derived Schemas can create a malicious JEXL expression which allows any administrator with sufficient entitlements for User read to access LinkedAccount's (if present) or Manager's (if defined) sensitive information, possibly including hashed credentials.
This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 Through 4.0.7, from 4.1.0-M0 through 4.1.2.
Users are recommended to upgrade to version 4.0.8 / 4.1.3, which fix this issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 4.0.8 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 4.1.3
Event History
Frequently Asked Questions
Who can exploit this issue, and what access is required?
An administrator needs adequate entitlements for Derived Schemas to create a malicious JEXL expression. An administrator with sufficient User read entitlements can then access the exposed LinkedAccount or Manager information.
What information may be exposed?
The issue can expose sensitive information from a user's LinkedAccount, if present, or Manager, if defined. The exposed data may include hashed credentials.
Which Apache Syncope versions are affected and which releases fix the issue?
Affected releases are 3.0.0-M0 through 3.0.16, 4.0.0-M0 through 4.0.7, and 4.1.0-M0 through 4.1.2. Upgrade to 4.0.8 or 4.1.3 to fix the issue.