VulnSea

org.apache.syncope.core:syncope-core-spring vulnerabilities

CVEs whose affected-version data names the org.apache.syncope.core:syncope-core-spring package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

4 CVEsRSS

CVE-2026-87785Critical· 9.1
1w ago

Authentication bypass by spoofing vulnerability in Apache Syncope. When the configured JWKS settings for internal JWT authentication are disclosed (at least protocol and key), an attacker can spoof another user's privileges after comp…

Authentication bypass by spoofing vulnerability in Apache Syncope. When the configured JWKS settings for internal JWT authentication are disclosed (at least protocol and key), an attacker can spoof another user's privileges after comp…

MidnightApache Software Foundation · org.apache.syncope.core:syncope-core-springEPSS 0.51%via NVD
CVE-2026-87779High· 7.5
1w ago

Insertion of sensitive information into log file vulnerability in Apache Syncope. When AES key of non-standard length (not 16/24/32 bytes) is configured, Syncope will pad the provided value with random characters

Insertion of sensitive information into log file vulnerability in Apache Syncope. When AES key of non-standard length (not 16/24/32 bytes) is configured, Syncope will pad the provided value with random characters. The resulting key va…

TwilightApache Software Foundation · org.apache.syncope.core:syncope-core-springEPSS 0.41%via NVD
CVE-2026-78330Critical· 9.8
1w ago

Incorrect privilege assignment vulnerability in Apache Syncope. When the configured JWKS settings for internal JWT authentication are disclosed (at least protocol and key), an attacker can obtain admin privileges after completing a succ…

Incorrect privilege assignment vulnerability in Apache Syncope. When the configured JWKS settings for internal JWT authentication are disclosed (at least protocol and key), an attacker can obtain admin privileges after completing a succ…

MidnightApache Software Foundation · org.apache.syncope.core:syncope-core-springEPSS 0.60%via NVD
CVE-2026-77147Medium· 6.5
1w ago

Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Syncope. An administrator with adequate entitlements for Implementations can create a malicious Groovy Command class containing untrusted code in their Co…

Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Syncope. An administrator with adequate entitlements for Implementations can create a malicious Groovy Command class containing untrusted code in their Co…

SunlitApache Software Foundation · org.apache.syncope.core:syncope-core-springEPSS 0.28%via NVD
org.apache.syncope.core:syncope-core-spring vulnerabilities (CVEs) · VulnSea