Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.1

CVE-2026-87802: Apache Syncope can allow forged login tokens

CVE-2026-87802 · published 11 days ago
Summary

If Apache Syncope is set up for OAuth 2.0 without a proper key source, an attacker can create fake authentication tokens and act as any user. This could give the attacker full access to services that rely on Syncope for identity checks. Update Syncope to version 4.0.8 or 4.1.3 (or later) to close the gap.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
apache software foundation apache syncope <= 3.0.16
Original advisory text
Improper verification of cryptographic signature vulnerability in Apache Syncope. When SRA is configured for OAuth 2.0 without JWKS set URI assigned, an attacker can forge arbitrary JWTs to impe...
Improper verification of cryptographic signature vulnerability in Apache Syncope.



When SRA is configured for OAuth 2.0 without JWKS set URI assigned, an attacker can forge arbitrary JWTs to impersonate any user identity and permissions, gaining full access to services proxied by SRA.

This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 through 4.0.7, from 4.1.0-M0 through 4.1.2.



Users are recommended to upgrade to version 4.0.8 / 4.1.3, which fix this issue.
Severity
9.1 Critical
Exploitation
EPSS <1%
Type
CWE-347Improper Verification of Cryptographic Signature
Timeline
Published14 Sep 2026
Updated19 Sep 2026
First seen14 Sep 2026
Sources
CVE-2026-87802 · MITRE
Track software like this
Free during beta