VYPR
Unrated severityNVD Advisory· Published May 25, 2026· Updated May 25, 2026

Apache Syncope: JexlContextBuilder Information Disclosure

CVE-2026-42797

Description

Exposure of Sensitive Information Through Data Queries vulnerability in Apache Syncope.

An administrator with adequate entitlements for Derived Schemas can create a malicious JEXL expression which allows any administrator with sufficient entitlements for User read to access User-related security-sensitive information.

This issue affects Apache Syncope: 3.0 through 3.0.16, 4.0 through 4.0.5, 4.1.0.

Users are recommended to upgrade to version 4.0.6 / 4.1.1, which fix this issue by further restricting the JEXL expression definition.

Affected products

2
  • Apache/Syncopeinferred2 versions
    >=3.0,<=3.0.16 || >=4.0,<=4.0.5 || =4.1.0+ 1 more
    • (no CPE)range: >=3.0,<=3.0.16 || >=4.0,<=4.0.5 || =4.1.0
    • (no CPE)range: >=3.0, <=3.0.16 / >=4.0, <=4.0.5 / =4.1.0

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.