CVE-2026-78336
Deferred Deferred - Pending Action

Information Exposure in Apache Syncope

Vulnerability report for CVE-2026-78336, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-14

Last updated on: 2026-09-14

Assigner: Apache Software Foundation

Description

Insertion of sensitive information into sent data vulnerability in Apache Syncope. Any authenticated user can query for the list of available OIDC providers configured for SSO with Console and Enduser. The returned payload contains all configuration settings, including client secrets, regardless of the entitlements owned by the caller. This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 through 4.0.7, from 4.1.0-M0 through 4.1.2. Users are recommended to upgrade to version 4.0.8 / 4.1.3, which fix this issue.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-14
Last Modified
2026-09-14
Generated
2026-09-15
AI Q&A
2026-09-14
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 5 associated CPEs
Vendor Product Version / Range
apache syncope From 3.0.0-M0 (inc) to 3.0.16 (inc)
apache syncope From 4.0.0-M0 (inc) to 4.0.7 (inc)
apache syncope From 4.1.0-M0 (inc) to 4.1.2 (inc)
apache syncope 4.0.8
apache syncope 4.1.3

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-201 The code transmits data to another actor, but a portion of the data includes sensitive information that should not be accessible to that actor.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in Apache Syncope allows any authenticated user to query and retrieve a list of OIDC providers configured for single sign-on (SSO) with Console and Enduser. The returned data includes sensitive configuration details such as client secrets, regardless of the user's permissions.

Detection Guidance

Check Apache Syncope logs for unauthorized queries to OIDC provider configurations. Look for requests to endpoints that return sensitive data like client secrets. Verify if any user accounts have accessed configuration endpoints without proper entitlements.

Impact Analysis

An attacker could exploit this to gain access to client secrets used for authentication with OIDC providers. This could lead to unauthorized access to systems, data breaches, or further attacks on connected services using the compromised credentials.

Compliance Impact

This vulnerability could result in unauthorized access to sensitive data, violating GDPR's data protection principles or HIPAA's security requirements for protected health information. Organizations may face compliance violations, legal penalties, and reputational damage.

Mitigation Strategies

Upgrade Apache Syncope to version 4.0.8 or 4.1.3 immediately. Temporarily restrict access to configuration endpoints until the upgrade is complete. Review all OIDC provider configurations and rotate any exposed client secrets.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-78336. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart