CVE-2026-73191
Deferred Deferred - Pending Action

Open Redirect in Apache Syncope via CAS Authentication

Vulnerability report for CVE-2026-73191, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-14

Last updated on: 2026-09-14

Assigner: Apache Software Foundation

Description

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Apache Syncope. When the Syncope SRA is configured for CAS authentication, the target Apereo CAS instance's URL is calculated by unconditionally looking at client-supplied forwarded HTTP headers. This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 Through 4.0.7, from 4.1.0-M0 through 4.1.2. Users are recommended to upgrade to version 4.0.8 / 4.1.3, which fix this issue.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-14
Last Modified
2026-09-14
Generated
2026-09-15
AI Q&A
2026-09-14
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 5 associated CPEs
Vendor Product Version / Range
apache syncope From 3.0.0-M0 (inc) to 3.0.16 (inc)
apache syncope From 4.0.0-M0 (inc) to 4.0.7 (inc)
apache syncope From 4.1.0-M0 (inc) to 4.1.2 (inc)
apache syncope 4.0.8
apache syncope 4.1.3

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-601 The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is an Open Redirect vulnerability in Apache Syncope. When configured for CAS authentication, the system uses client-supplied forwarded HTTP headers to calculate the target CAS instance URL without validation. This allows attackers to manipulate the URL and redirect users to untrusted sites.

Detection Guidance

To detect this vulnerability, check if your Apache Syncope instance is configured for CAS authentication and verify if it unconditionally trusts client-supplied forwarded HTTP headers for URL calculation. Inspect network traffic for unexpected redirects to untrusted domains.

Impact Analysis

Attackers could trick users into visiting malicious sites by redirecting them from a trusted Apache Syncope domain. This may lead to phishing attacks, credential theft, or malware distribution. Users with administrative access are particularly at risk.

Compliance Impact

This vulnerability allows URL redirection to untrusted sites, which could be exploited for phishing attacks. Such attacks may lead to unauthorized access to sensitive data, potentially violating GDPR (data protection) and HIPAA (health information privacy) compliance by exposing personal or health-related data.

Mitigation Strategies

Upgrade Apache Syncope to version 4.0.8, 4.1.3, or later to fix the vulnerability. If using CAS authentication with Syncope SRA, ensure the target CAS instance URL is not derived from untrusted client-supplied headers.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-73191. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart