Feed/CVE-2026-42797
CVE-2026-42797MEDIUMCVSS 4.9

Apache Syncope Vulnerable to Exposure of Sensitive Information Through Data Queries

Published May 26, 2026·Updated Jun 30, 2026

NVD Description

Exposure of Sensitive Information Through Data Queries vulnerability in Apache Syncope. An administrator with adequate entitlements for Derived Schemas can create a malicious JEXL expression which allows any administrator with sufficient entitlements for User read to access User-related security-sensitive information. This issue affects Apache Syncope: 3.0 through 3.0.16, 4.0 through 4.0.5, 4.1.0. Users are recommended to upgrade to version 4.0.6 / 4.1.1, which fix this issue by further restricting the JEXL expression definition.

Affected Packages (1)

org.apache.syncope.core:syncope-core-provisioning-apiMAVEN
From 3.0.0-M0
Fixed in = 3.0.16

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free