CRITICAL 9.8 CVE-2026-73579 Published 14 Sept 2026

Apache Syncope Authorization Bypass

Worried this affects one of your servers?

Apache Syncope, a powerful identity management system, is affected by an authorization bypass vulnerability.

This issue, present in versions 3.0.0-M0 to 3.0.16, 4.0.0-M0 to 4.0.7, and 4.1.0-M0 to 4.1.2, allows unauthorized users to bypass realms filter, potentially accessing restricted data.

Users are advised to upgrade to version 4.0.8 or 4.1.3 to mitigate this risk.

Reference: CVE-2026-73579 on NVD

← Back to Security News