CRITICAL 9.1 CVE-2026-87785 Published 14 Sept 2026

Apache Syncope JWT Spoofing Bug

Worried this affects one of your servers?

Apache Syncope, a popular identity management platform, is affected by a serious authentication bypass vulnerability.

Syncope versions 3.0.0-M0 to 3.0.16, 4.0.0-M0 to 4.0.7, and 4.1.0-M0 to 4.1.2 are vulnerable. An attacker can exploit this issue to impersonate other users by spoofing JWT tokens.

Users are advised to upgrade to version 4.0.8 or 4.1.3 to mitigate this risk.

Reference: CVE-2026-87785 on NVD

← Back to Security News