๐Ÿ” CVE Alert

CVE-2026-62183

UNKNOWN 0.0

Apache Syncope: User self-service privilege escalation

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Improper Privilege Management vulnerability in Apache Syncope. When: * the all-Java user workflow adapter is configured, or * the Flowable user workflow adapter is configured, bearing a BPMN definition not requiring admin approval for user self registration of self update requests the following scenario could happen. A REST API call can allow the user to grant themselves one or more of defined Roles, thus gaining their Entitlements and becoming in fact an administrator; the actual Entitlements gained depend on the Roles that are effectively defined on the specific Syncope deployment. This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 Through 4.0.6, from 4.1.0-M0 through 4.1.1. Users are recommended to upgrade to version 4.0.7 / 4.1.2, which fix this issue.

CWE CWE-269
Vendor apache software foundation
Product apache syncope
Published Jul 20, 2026
Last Updated Jul 20, 2026
Stay Ahead of the Next One

Get instant alerts for apache software foundation apache syncope

Be the first to know when new unknown vulnerabilities affecting apache software foundation apache syncope are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Apache Software Foundation / Apache Syncope
3.0.0-M0 โ‰ค 3.0.16 4.0.0-M0 โ‰ค 4.0.6 4.1.0-M0 โ‰ค 4.1.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
lists.apache.org: https://lists.apache.org/thread/6r8cngvy43y2yk4jj3w060dt8vx0yzpr openwall.com: http://www.openwall.com/lists/oss-security/2026/07/20/9

Credits

Nic Jones elin kai