CVE-2026-73370

Summary

Incorrect Authorization vulnerability in Apache Syncope.

Delegated administration security checks performed by Reconciliation service's pull and push, being incomplete, could accept calls by administrator not provided with adequate entitlements.

This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 Through 4.0.7, from 4.1.0-M0 through 4.1.2.

Users are recommended to upgrade to version 4.0.8 / 4.1.3, which fix this issue.

Affected Software

VendorProductVersion RangeStatus
Apache Software FoundationApache Syncope3.0.0-M0 <= 3.0.16affected
Apache Software FoundationApache Syncope4.0.0-M0 <= 4.0.7affected
Apache Software FoundationApache Syncope4.1.0-M0 <= 4.1.2affected

Weaknesses

  • CWE-863: CWE-863 Incorrect Authorization

ADP Enrichment

CVE Program Container

Additional References

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: yes
    • Technical Impact: total

References