VYPR
Unrated severityNVD Advisory· Published Sep 14, 2026

CVE-2026-73370

CVE-2026-73370

Description

Incorrect Authorization vulnerability in Apache Syncope.

Delegated administration security checks performed by Reconciliation service's pull and push, being incomplete, could accept calls by administrator not provided with adequate entitlements.

This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 Through 4.0.7, from 4.1.0-M0 through 4.1.2.

Users are recommended to upgrade to version 4.0.8 / 4.1.3, which fix this issue.

Affected products

1
  • Apache/Syncopellm-fuzzy
    Range: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 Through 4.0.7, from 4.1.0-M0 through 4.1.2

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.

CVE-2026-73370 · VYPR