https://seclists.org/oss-sec/2026/q3/773: CVE-2026-87779: Apache Syncope: AES Sect Key disclosuvia log output
Published Sep 14, 2026
·Updated
Affected Software
3 affected components
Apache Syncope>=3.0.15<=3.0.16
Apache Syncope>=4.0.3<=4.0.7
Apache Syncope>=4.1.0-M0<=4.1.2
Frequently Asked Questions
1
Which deployments are exposed to this issue?
Deployments using syncope-core-spring 3.0.15 through 3.0.16, 4.0.3 through 4.0.7, or 4.1.0-M0 through 4.1.2 are affected only when an AES key with a length other than 16, 24, or 32 bytes is configured.
2
What condition causes the sensitive value to be written to logs?
The condition occurs when Syncope is configured with a non-standard-length AES key. Syncope pads the supplied value with random characters and logs the resulting key value.
3
What versions resolve the issue?
Upgrade to Apache Syncope version 4.0.8 or 4.1.3, which fix the logging of the resulting AES key value.