VulnSea

org.apache.syncope.core:syncope-core-provisioning-java vulnerabilities

CVEs whose affected-version data names the org.apache.syncope.core:syncope-core-provisioning-java package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

4 CVEsRSS

CVE-2026-75015Medium· 4.9
1w ago

Insufficiently Protected Credentials vulnerability in Apache Syncope. Audit events, when sent to the configured store, are not sufficiently masked for the sensitive values they might carry on their payloads, thus allowing administrators…

Insufficiently Protected Credentials vulnerability in Apache Syncope. Audit events, when sent to the configured store, are not sufficiently masked for the sensitive values they might carry on their payloads, thus allowing administrators…

SunlitApache Software Foundation · org.apache.syncope.core:syncope-core-provisioning-javaEPSS 0.38%via NVD
CVE-2026-73470Critical· 9.8
1w ago

Improper Privilege Management vulnerability in Apache Syncope. Delegations can be created or updated with Roles not owned by the delegating User, or not for the same Realm subtree under the delegation management was granted for. …

Improper Privilege Management vulnerability in Apache Syncope. Delegations can be created or updated with Roles not owned by the delegating User, or not for the same Realm subtree under the delegation management was granted for. …

MidnightApache Software Foundation · org.apache.syncope.core:syncope-core-provisioning-javaEPSS 0.48%via NVD
CVE-2026-73178High· 7.5
1w ago

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Syncope. An administrator with adequate entitlements can get access via REST to the list of existing Access Tokens, including their signed JWT body. Thes…

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Syncope. An administrator with adequate entitlements can get access via REST to the list of existing Access Tokens, including their signed JWT body. Thes…

TwilightApache Software Foundation · org.apache.syncope.core:syncope-core-provisioning-javaEPSS 0.41%via NVD
CVE-2026-73195High· 7.3
1w ago

Improper Encoding or Escaping of Output vulnerability in Apache Syncope. Authenticated users can store a spreadsheet formula payload in one of their own plain attributes

Improper Encoding or Escaping of Output vulnerability in Apache Syncope. Authenticated users can store a spreadsheet formula payload in one of their own plain attributes. When such users are included in a CSV export and the generated …

TwilightApache Software Foundation · org.apache.syncope.core:syncope-core-provisioning-javaEPSS 0.34%via NVD
org.apache.syncope.core:syncope-core-provisioning-java vulnerabilities (CVEs) · VulnSea