{"id":"CVE-2026-77883","title":"Exposure of sensitive information through data queries vulnerability in Apache Syncope.\n\nAn administrator with adequate entitlements for Derived Schemas can create a malicious JEXL expression which allows any administrator with sufficien…","summary":"Exposure of sensitive information through data queries vulnerability in Apache Syncope.\n\nAn administrator with adequate entitlements for Derived Schemas can create a malicious JEXL expression which allows any administrator with sufficien…","severity":"medium","cvss":4.9,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N","cwe":["CWE-202"],"vendor":"Apache Software Foundation","product":"org.apache.syncope.core:syncope-core-provisioning-api","affected":["org.apache.syncope.core:syncope-core-provisioning-api >= 3.0.0-M0 <= 3.0.16","org.apache.syncope.core:syncope-core-provisioning-api >= 4.0.0-M0 <= 4.0.7","org.apache.syncope.core:syncope-core-provisioning-api >= 4.1.0-M0 <= 4.1.2"],"published":"2026-09-14","updated":"2026-09-14","sourceUpdated":"2026-09-14T20:58:48.430","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-77883","references":[{"url":"https://lists.apache.org/thread/oshwdz2k4cl3042y39zq0yl4qkxbd83p","label":"security@apache.org"},{"url":"http://www.openwall.com/lists/oss-security/2026/09/14/17","label":"af854a3a-2127-422b-91ae-364da2661108"}],"tags":["nvd","cve.org"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2026-09-14T19:15:58.821229Z"},"ingestedAt":"2026-09-14T15:23:07.432Z","epss":0.00375,"epssPercentile":0.31241,"slug":"CVE-2026-77883","body":"## Overview\n\nExposure of sensitive information through data queries vulnerability in Apache Syncope.\n\nAn administrator with adequate entitlements for Derived Schemas can create a malicious JEXL expression which allows any administrator with sufficient entitlements for User read to access LinkedAccount's (if present) or Manager's (if defined) sensitive information, possibly including hashed credentials.\n\nThis issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 Through 4.0.7, from 4.1.0-M0 through 4.1.2.\n\nUsers are recommended to upgrade to version 4.0.8 / 4.1.3, which fix this issue.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":27,"depthScoreParts":{"impact":27,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[{"seq":203262,"id":"CVE-2026-77883","ts":1789416900241,"field":"cvss","old":null,"new":"4.9"},{"seq":203261,"id":"CVE-2026-77883","ts":1789416900241,"field":"severity","old":"none","new":"medium"}]}