{"id":"CVE-2026-73191","title":"URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Apache Syncope.\n\n\n\n\n\nWhen the Syncope SRA is configured for CAS authentication, the target Apereo CAS instance's URL is calculated by unconditionally looking at client-…","summary":"URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Apache Syncope.\n\n\n\n\n\nWhen the Syncope SRA is configured for CAS authentication, the target Apereo CAS instance's URL is calculated by unconditionally looking at client-…","severity":"medium","cvss":6.1,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","cwe":["CWE-601"],"vendor":"Apache Software Foundation","product":"org.apache.syncope:syncope-sra","affected":["org.apache.syncope:syncope-sra >= 3.0.0-M0 <= 3.0.16","org.apache.syncope:syncope-sra >= 4.0.0-M0 <= 4.0.7","org.apache.syncope:syncope-sra >= 4.1.0-M0 <= 4.1.2"],"published":"2026-09-14","updated":"2026-09-14","sourceUpdated":"2026-09-14T20:58:48.430","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-73191","references":[{"url":"https://lists.apache.org/thread/vx9bons1znhdkdpsxwjpy6qqqjc8xqtk","label":"security@apache.org"},{"url":"http://www.openwall.com/lists/oss-security/2026/09/14/5","label":"af854a3a-2127-422b-91ae-364da2661108"}],"tags":["nvd","cve.org"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2026-09-14T19:32:24.226704Z"},"ingestedAt":"2026-09-14T15:23:07.422Z","epss":0.00289,"epssPercentile":0.21658,"slug":"CVE-2026-73191","body":"## Overview\n\nURL Redirection to Untrusted Site ('Open Redirect') vulnerability in Apache Syncope.\n\n\n\n\n\nWhen the Syncope SRA is configured for CAS authentication, the target Apereo CAS instance's URL is calculated by unconditionally looking at client-supplied forwarded HTTP headers.\n\nThis issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 Through 4.0.7, from 4.1.0-M0 through 4.1.2.\n\nUsers are recommended to upgrade to version 4.0.8 / 4.1.3, which fix this issue.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":34,"depthScoreParts":{"impact":33.6,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[{"seq":203270,"id":"CVE-2026-73191","ts":1789416901027,"field":"cvss","old":null,"new":"6.1"},{"seq":203269,"id":"CVE-2026-73191","ts":1789416901027,"field":"severity","old":"none","new":"medium"}]}