Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.8
CVE-2026-75030: Apache Syncope admins could change many group members
CVE-2026-75030 · published 11 days ago
Summary
In Apache Syncope versions up to 3.0.16, 4.0.7, and 4.1.2, an administrator who is only allowed to run tasks can add or remove large numbers of users from groups even without proper group‑management rights. This could unintentionally give people access they shouldn’t have or take away access from those who need it. The issue is fixed in Apache Syncope 4.0.8 and 4.1.3, so upgrade to one of those versions promptly.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| apache software foundation | apache syncope | <= 3.0.16 |
Original advisory text
Missing Authorization vulnerability in Apache Syncope.
An administrator with task execution entitlements might be able to mass (de)provision group members, regardless of their group-related admi...
Missing Authorization vulnerability in Apache Syncope.
An administrator with task execution entitlements might be able to mass (de)provision group members, regardless of their group-related administration capabilities.
This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 Through 4.0.7, from 4.1.0-M0 through 4.1.2.
Users are recommended to upgrade to version 4.0.8 / 4.1.3, which fix this issue.
An administrator with task execution entitlements might be able to mass (de)provision group members, regardless of their group-related administration capabilities.
This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 Through 4.0.7, from 4.1.0-M0 through 4.1.2.
Users are recommended to upgrade to version 4.0.8 / 4.1.3, which fix this issue.
Severity
9.8
Critical
Exploitation
EPSS <1%
Type
CWE-862Missing Authorization
Timeline
Published14 Sep 2026
Updated25 Sep 2026
First seen14 Sep 2026
Track software like this
Free during beta