---
id: CVE-2026-75015
title: >-
  Insufficiently Protected Credentials vulnerability in Apache Syncope.


  Audit events, when sent to the configured store, are not sufficiently masked
  for the sensitive values they might carry on their payloads, thus allowing
  administrators…
summary: >-
  Insufficiently Protected Credentials vulnerability in Apache Syncope.


  Audit events, when sent to the configured store, are not sufficiently masked
  for the sensitive values they might carry on their payloads, thus allowing
  administrators…
severity: medium
cvss: 4.9
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-522
vendor: Apache Software Foundation
product: 'org.apache.syncope.core:syncope-core-provisioning-java'
affected:
  - 'org.apache.syncope.core:syncope-core-provisioning-java >= 3.0.0-M0 <= 3.0.16'
  - 'org.apache.syncope.core:syncope-core-provisioning-java >= 4.0.0-M0 <= 4.0.7'
  - 'org.apache.syncope.core:syncope-core-provisioning-java >= 4.1.0-M0 <= 4.1.2'
published: '2026-09-14'
updated: '2026-09-14'
sourceUpdated: '2026-09-14T20:58:48.430'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-75015'
references:
  - url: 'https://lists.apache.org/thread/nns7711kyomy28r7rh2pps06ymd5s99k'
    label: security@apache.org
  - url: 'http://www.openwall.com/lists/oss-security/2026/09/14/12'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-14T19:26:29.295519Z'
ingestedAt: '2026-09-14T15:23:07.429Z'
epss: 0.00375
epssPercentile: 0.31397
---

## Overview

Insufficiently Protected Credentials vulnerability in Apache Syncope.

Audit events, when sent to the configured store, are not sufficiently masked for the sensitive values they might carry on their payloads, thus allowing administrators to access such sensitive values.





This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 Through 4.0.7, from 4.1.0-M0 through 4.1.2.


Users are recommended to upgrade to version 4.0.8 / 4.1.3, which fix this issue.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
