---
id: CVE-2026-78336
title: >-
  Insertion of sensitive information into sent data vulnerability in Apache
  Syncope.




  Any authenticated user can query for the list of available OIDC providers
  configured for SSO with Console and Enduser
summary: >-
  Insertion of sensitive information into sent data vulnerability in Apache
  Syncope.




  Any authenticated user can query for the list of available OIDC providers
  configured for SSO with Console and Enduser. The returned payload contains al…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-201
vendor: Apache Software Foundation
product: 'org.apache.syncope.ext.oidcc4ui:syncope-ext-oidcc4ui-logic'
affected:
  - >-
    org.apache.syncope.ext.oidcc4ui:syncope-ext-oidcc4ui-logic >= 3.0.0-M0 <=
    3.0.16
  - >-
    org.apache.syncope.ext.oidcc4ui:syncope-ext-oidcc4ui-logic >= 4.0.0-M0 <=
    4.0.7
  - >-
    org.apache.syncope.ext.oidcc4ui:syncope-ext-oidcc4ui-logic >= 4.1.0-M0 <=
    4.1.2
published: '2026-09-14'
updated: '2026-09-14'
sourceUpdated: '2026-09-14T20:58:48.430'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-78336'
references:
  - url: 'https://lists.apache.org/thread/h399sqmf4wgnfxxpd6x9lm3m672rrsjt'
    label: security@apache.org
  - url: 'http://www.openwall.com/lists/oss-security/2026/09/14/20'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-09-14T19:21:20.096180Z'
ingestedAt: '2026-09-14T15:23:07.432Z'
epss: 0.00432
epssPercentile: 0.34884
---

## Overview

Insertion of sensitive information into sent data vulnerability in Apache Syncope.



Any authenticated user can query for the list of available OIDC providers configured for SSO with Console and Enduser. The returned payload contains all configuration settings, including client secrets, regardless of the entitlements owned by the caller.



This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 through 4.0.7, from 4.1.0-M0 through 4.1.2.



Users are recommended to upgrade to version 4.0.8 / 4.1.3, which fix this issue.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
