SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-73370

CRITICAL · CVSS 9.8

Source: NVD + CISA KEV + EPSS · Published 2026-09-14 · Last synced 2026-09-15

CyberRota Analysis

AI-Generated

Apache Syncope versions 3.0.0-M0 to 3.0.16, 4.0.0-M0 to 4.0.7, and 4.1.0-M0 to 4.1.2 are vulnerable due to incomplete delegated administration security checks in the Reconciliation service, allowing unauthorized administrators to execute actions without proper entitlements. This critical vulnerability, rated CVSS 9.8, poses a significant risk of unauthorized access and potential data breaches. Organizations using affected versions should prioritize upgrading to versions 4.0.8 or 4.1.3 to mitigate this risk.

CVE
CVE-2026-73370
Severity
CRITICAL
CVSS
9.8
EPSS
N/A
Apache

Original NVD Description

Incorrect Authorization vulnerability in Apache Syncope. Delegated administration security checks performed by Reconciliation service's pull and push, being incomplete, could accept calls by administrator not provided with adequate entitlements. This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 Through 4.0.7, from 4.1.0-M0 through 4.1.2. Users are recommended to upgrade to version 4.0.8 / 4.1.3, which fix this issue.