Unrated severityNVD Advisory· Published Sep 14, 2026
CVE-2026-75015
CVE-2026-75015
Description
Insufficiently Protected Credentials vulnerability in Apache Syncope.
Audit events, when sent to the configured store, are not sufficiently masked for the sensitive values they might carry on their payloads, thus allowing administrators to access such sensitive values.
This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 Through 4.0.7, from 4.1.0-M0 through 4.1.2.
Users are recommended to upgrade to version 4.0.8 / 4.1.3, which fix this issue.
Affected products
1Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.