---
id: CVE-2026-73178
title: >-
  Exposure of Sensitive Information to an Unauthorized Actor vulnerability in
  Apache Syncope.


  An administrator with adequate entitlements can get access via REST to the
  list of existing Access Tokens, including their signed JWT body.

  Thes…
summary: >-
  Exposure of Sensitive Information to an Unauthorized Actor vulnerability in
  Apache Syncope.


  An administrator with adequate entitlements can get access via REST to the
  list of existing Access Tokens, including their signed JWT body.

  Thes…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-200
vendor: Apache Software Foundation
product: 'org.apache.syncope.core:syncope-core-provisioning-java'
affected:
  - 'org.apache.syncope.core:syncope-core-provisioning-java >= 3.0.0-M0 <= 3.0.16'
  - 'org.apache.syncope.core:syncope-core-provisioning-java >= 4.0.0-M0 <= 4.0.7'
  - 'org.apache.syncope.core:syncope-core-provisioning-java >= 4.1.0-M0 <= 4.1.2'
published: '2026-09-14'
updated: '2026-09-14'
sourceUpdated: '2026-09-14T20:58:48.430'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-73178'
references:
  - url: 'https://lists.apache.org/thread/owcdm0stb39mnkpyps0h6yw4gp2olnkj'
    label: security@apache.org
  - url: 'http://www.openwall.com/lists/oss-security/2026/09/14/4'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-09-14T19:29:30.325595Z'
ingestedAt: '2026-09-14T15:23:07.426Z'
epss: 0.00413
epssPercentile: 0.35347
---

## Overview

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Syncope.

An administrator with adequate entitlements can get access via REST to the list of existing Access Tokens, including their signed JWT body.
These values can be then used to perform further REST requests, impersonating users with higher administration entitlements.





This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 Through 4.0.7, from 4.1.0-M0 through 4.1.2.

Users are recommended to upgrade to version 4.0.8 / 4.1.3, which fix this issue.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
