SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-75015

MEDIUM · CVSS 4.9

Source: NVD + CISA KEV + EPSS · Published 2026-09-14 · Last synced 2026-09-15

CyberRota Analysis

AI-Generated

Apache Syncope versions 3.0.0-M0 through 3.0.16, 4.0.0-M0 through 4.0.7, and 4.1.0-M0 through 4.1.2 are vulnerable due to insufficiently protected credentials in audit event logs, potentially exposing sensitive information to administrators. This vulnerability could lead to unauthorized access to sensitive data, impacting the confidentiality of user credentials. Organizations using affected versions should prioritize upgrading to 4.0.8 or 4.1.3 to mitigate this risk.

CVE
CVE-2026-75015
Severity
MEDIUM
CVSS
4.9
EPSS
N/A
Apache

Original NVD Description

Insufficiently Protected Credentials vulnerability in Apache Syncope. Audit events, when sent to the configured store, are not sufficiently masked for the sensitive values they might carry on their payloads, thus allowing administrators to access such sensitive values. This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 Through 4.0.7, from 4.1.0-M0 through 4.1.2. Users are recommended to upgrade to version 4.0.8 / 4.1.3, which fix this issue.