CVE-2026-77883
Deferred Deferred - Pending Action

Sensitive Information Exposure in Apache Syncope via Malicious JEXL Queries

Vulnerability report for CVE-2026-77883, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-14

Last updated on: 2026-09-14

Assigner: Apache Software Foundation

Description

Exposure of sensitive information through data queries vulnerability in Apache Syncope. An administrator with adequate entitlements for Derived Schemas can create a malicious JEXL expression which allows any administrator with sufficient entitlements for User read to access LinkedAccount's (if present) or Manager's (if defined) sensitive information, possibly including hashed credentials. This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 Through 4.0.7, from 4.1.0-M0 through 4.1.2. Users are recommended to upgrade to version 4.0.8 / 4.1.3, which fix this issue.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-14
Last Modified
2026-09-14
Generated
2026-09-15
AI Q&A
2026-09-14
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 5 associated CPEs
Vendor Product Version / Range
apache syncope From 3.0.0-M0 (inc) to 3.0.16 (inc)
apache syncope From 4.0.0-M0 (inc) to 4.0.7 (inc)
apache syncope From 4.1.0-M0 (inc) to 4.1.2 (inc)
apache syncope 4.0.8
apache syncope 4.1.3

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-202 When trying to keep information confidential, an attacker can often infer some of the information by using statistics.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in Apache Syncope allows an administrator with specific permissions to create a malicious JEXL expression. This can expose sensitive information through data queries, including hashed credentials from LinkedAccount or Manager details if present.

Detection Guidance

This vulnerability involves malicious JEXL expressions in Apache Syncope. Detection requires reviewing Derived Schemas and User read entitlements for unauthorized access patterns. Check Apache Syncope logs for suspicious queries or expressions involving LinkedAccount or Manager data. Review user permissions for excessive entitlements.

Impact Analysis

An attacker with sufficient privileges could exploit this to access sensitive data such as hashed credentials, potentially leading to further security breaches or unauthorized access.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, violating compliance requirements for data protection standards like GDPR and HIPAA, which mandate strict controls over personal and health information.

Mitigation Strategies

Upgrade Apache Syncope to version 4.0.8 or 4.1.3 or later to fix the vulnerability. Ensure only administrators with necessary entitlements have access to Derived Schemas and User read permissions.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-77883. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart