CRITICAL
9.1 CVE-2026-87785 Published 14 Sept 2026
Apache Syncope JWT Spoofing Bug
Worried this affects one of your servers?
Apache Syncope, a popular identity management platform, is affected by a serious authentication bypass vulnerability.
Syncope versions 3.0.0-M0 to 3.0.16, 4.0.0-M0 to 4.0.7, and 4.1.0-M0 to 4.1.2 are vulnerable. An attacker can exploit this issue to impersonate other users by spoofing JWT tokens.
Users are advised to upgrade to version 4.0.8 or 4.1.3 to mitigate this risk.
Reference: CVE-2026-87785 on NVD
← Back to Security News