SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-75030

CRITICAL · CVSS 9.8

Source: NVD + CISA KEV + EPSS · Published 2026-09-14 · Last synced 2026-09-15

CyberRota Analysis

AI-Generated

A critical missing authorization vulnerability in Apache Syncope allows administrators with task execution entitlements to mass (de)provision group members without proper group-related administration capabilities. This flaw impacts versions 3.0.0-M0 through 3.0.16, 4.0.0-M0 through 4.0.7, and 4.1.0-M0 through 4.1.2. Organizations using affected versions should prioritize upgrading to 4.0.8 or 4.1.3 to mitigate potential unauthorized access and administrative actions.

CVE
CVE-2026-75030
Severity
CRITICAL
CVSS
9.8
EPSS
N/A
Apache

Original NVD Description

Missing Authorization vulnerability in Apache Syncope. An administrator with task execution entitlements might be able to mass (de)provision group members, regardless of their group-related administration capabilities. This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 Through 4.0.7, from 4.1.0-M0 through 4.1.2. Users are recommended to upgrade to version 4.0.8 / 4.1.3, which fix this issue.