Severity: low 

Affected versions:

- Apache Syncope (org.apache.syncope:syncope-sra) 3.0.0-M0 through 3.0.16
- Apache Syncope (org.apache.syncope:syncope-sra) 4.0.0-M0 through 4.0.7
- Apache Syncope (org.apache.syncope:syncope-sra) 4.1.0-M0 through 4.1.2

Description:

Improper verification of cryptographic signature vulnerability in Apache 
Syncope.



When SRA is configured for OAuth 2.0 without JWKS set URI assigned, an attacker 
can forge arbitrary JWTs to impersonate any user identity and permissions, 
gaining full access to services proxied by SRA.

This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 
through 4.0.7, from 4.1.0-M0 through 4.1.2.



Users are recommended to upgrade to version 4.0.8 / 4.1.3, which fix this issue.

Credit:

MopMonk AI (finder)

References:

https://syncope.apache.org/
https://www.cve.org/CVERecord?id=CVE-2026-87802

Reply via email to