CVE-2026-87802

Summary

Improper verification of cryptographic signature vulnerability in Apache Syncope.

When SRA is configured for OAuth 2.0 without JWKS set URI assigned, an attacker can forge arbitrary JWTs to impersonate any user identity and permissions, gaining full access to services proxied by SRA.

This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 through 4.0.7, from 4.1.0-M0 through 4.1.2.

Users are recommended to upgrade to version 4.0.8 / 4.1.3, which fix this issue.

Affected Software

VendorProductVersion RangeStatus
Apache Software FoundationApache Syncope3.0.0-M0 <= 3.0.16affected
Apache Software FoundationApache Syncope4.0.0-M0 <= 4.0.7affected
Apache Software FoundationApache Syncope4.1.0-M0 <= 4.1.2affected

Weaknesses

  • CWE-347: CWE-347 Improper verification of cryptographic signature

ADP Enrichment

CVE Program Container

Additional References

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: yes
    • Technical Impact: total

References