VYPR
Medium severity4.9NVD Advisory· Published May 25, 2026· Updated Jul 24, 2026

CVE-2026-42797

CVE-2026-42797

Description

Exposure of Sensitive Information Through Data Queries vulnerability in Apache Syncope.

An administrator with adequate entitlements for Derived Schemas can create a malicious JEXL expression which allows any administrator with sufficient entitlements for User read to access User-related security-sensitive information.

This issue affects Apache Syncope: 3.0 through 3.0.16, 4.0 through 4.0.5, 4.1.0.

Users are recommended to upgrade to version 4.0.6 / 4.1.1, which fix this issue by further restricting the JEXL expression definition.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
org.apache.syncope.core:syncope-core-provisioning-apiMaven
>= 3.0.0-M0, <= 3.0.16
org.apache.syncope.core:syncope-core-provisioning-apiMaven
>= 4.0.0-M0, < 4.0.64.0.6
org.apache.syncope.core:syncope-core-provisioning-apiMaven
>= 4.1.0-M0, < 4.1.14.1.1

Affected products

4
  • Apache/Syncopeinferred4 versions
    >=3.0,<=3.0.16 || >=4.0,<=4.0.5 || =4.1.0+ 3 more
    • (no CPE)range: >=3.0,<=3.0.16 || >=4.0,<=4.0.5 || =4.1.0
    • cpe:2.3:a:apache:syncope:*:*:*:*:*:*:*:*range: >=3.0.0,<=3.0.16
    • cpe:2.3:a:apache:syncope:4.1.0:*:*:*:*:*:*:*
    • (no CPE)range: 3.0 - 3.0.16, 4.0 - 4.0.5, 4.1.0

Patches

Vulnerability mechanics

References

4

News mentions

2