org.apache.syncope:syncope-sra vulnerabilities
CVEs whose affected-version data names the org.apache.syncope:syncope-sra package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2026-87802Critical· 9.1Improper verification of cryptographic signature vulnerability in Apache Syncope. When SRA is configured for OAuth 2.0 without JWKS set URI assigned, an attacker can forge arbitrary JWTs to impersonate any user identity and permission…
Improper verification of cryptographic signature vulnerability in Apache Syncope. When SRA is configured for OAuth 2.0 without JWKS set URI assigned, an attacker can forge arbitrary JWTs to impersonate any user identity and permission…
▾ MidnightApache Software Foundation · org.apache.syncope:syncope-sraEPSS 0.26%via NVD
CVE-2026-73191Medium· 6.1URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Apache Syncope. When the Syncope SRA is configured for CAS authentication, the target Apereo CAS instance's URL is calculated by unconditionally looking at client-…
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Apache Syncope. When the Syncope SRA is configured for CAS authentication, the target Apereo CAS instance's URL is calculated by unconditionally looking at client-…
▾ SunlitApache Software Foundation · org.apache.syncope:syncope-sraEPSS 0.29%via NVD