๐Ÿ” CVE Alert

CVE-2026-78336

HIGH 7.5

Apache Syncope: OIDCC4UI provider list discloses client secrets to any authenticated user

CVSS Score
7.5
EPSS Score
0.0%
EPSS Percentile
0th

Insertion of sensitive information into sent data vulnerability in Apache Syncope. Any authenticated user can query for the list of available OIDC providers configured for SSO with Console and Enduser. The returned payload contains all configuration settings, including client secrets, regardless of the entitlements owned by the caller. This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 through 4.0.7, from 4.1.0-M0 through 4.1.2. Users are recommended to upgrade to version 4.0.8 / 4.1.3, which fix this issue.

CWE CWE-201
Vendor apache software foundation
Product apache syncope
Published Sep 14, 2026
Last Updated Sep 14, 2026
Stay Ahead of the Next One

Get instant alerts for apache software foundation apache syncope

Be the first to know when new high vulnerabilities affecting apache software foundation apache syncope are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Apache Software Foundation / Apache Syncope
3.0.0-M0 โ‰ค 3.0.16 4.0.0-M0 โ‰ค 4.0.7 4.1.0-M0 โ‰ค 4.1.2

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
lists.apache.org: https://lists.apache.org/thread/h399sqmf4wgnfxxpd6x9lm3m672rrsjt openwall.com: http://www.openwall.com/lists/oss-security/2026/09/14/20

Credits

Moritz Theile