CVE-2026-87785: Apache Syncope: JWT subject spoofing
Authentication bypass by spoofing vulnerability in Apache Syncope.
When the configured JWKS settings for internal JWT authentication are disclosed (at least protocol and key), an attacker can spoof another user's privileges after completing a successful authentication and obtaining a valid JWT.
This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 through 4.0.7, from 4.1.0-M0 through 4.1.2.
Users are recommended to upgrade to version 4.0.8 / 4.1.3, which fix this issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache Syncopeto a version that resolves this vulnerability.Fixed in 4.0.8 - Upgrade
Upgrade
Apache Syncopeto a version that resolves this vulnerability.Fixed in 4.1.3
Event History
Frequently Asked Questions
What must an attacker have to exploit this issue?
The attacker must first complete a successful authentication and obtain a valid JWT. They also need the configured JWKS settings for internal JWT authentication to be disclosed, including at least the protocol and key.
Which deployments are exposed?
Apache Syncope deployments in the affected version ranges are exposed when their internal JWT-authentication JWKS settings have been disclosed. The issue affects versions 3.0.0-M0 through 3.0.16, 4.0.0-M0 through 4.0.7, and 4.1.0-M0 through 4.1.2.
What is the remediation?
Upgrade to Apache Syncope 4.0.8 or 4.1.3, which fix the issue.