CVE-2026-87802: Apache Syncope: SRA OAuth2 JWT signature verification bypass
Improper verification of cryptographic signature vulnerability in Apache Syncope.
When SRA is configured for OAuth 2.0 without JWKS set URI assigned, an attacker can forge arbitrary JWTs to impersonate any user identity and permissions, gaining full access to services proxied by SRA.
This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 through 4.0.7, from 4.1.0-M0 through 4.1.2.
Users are recommended to upgrade to version 4.0.8 / 4.1.3, which fix this issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache Syncopeto a version that resolves this vulnerability.Fixed in 4.0.8 / 4.1.3
Event History
Frequently Asked Questions
Which deployments are exposed?
Deployments using SRA with OAuth 2.0 where no JWKS set URI is assigned are exposed. The affected release ranges are 3.0.0-M0 through 3.0.16, 4.0.0-M0 through 4.0.7, and 4.1.0-M0 through 4.1.2.
What does an attacker need to exploit this issue?
An attacker needs the SRA OAuth 2.0 configuration to lack an assigned JWKS set URI. In that condition, they can forge JWTs for arbitrary identities and permissions.
What versions resolve the issue?
Upgrade to Apache Syncope 4.0.8 or 4.1.3, which fix the vulnerability.