SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-87785

CRITICAL · CVSS 9.1

Source: NVD + CISA KEV + EPSS · Published 2026-09-14 · Last synced 2026-09-15

CyberRota Analysis

AI-Generated

Apache Syncope versions 3.0.0-M0 through 3.0.16, 4.0.0-M0 through 4.0.7, and 4.1.0-M0 through 4.1.2 are vulnerable to an authentication bypass due to JWKS settings disclosure, allowing attackers to spoof user privileges after obtaining a valid JWT. Organizations using affected versions should prioritize upgrading to 4.0.8 or 4.1.3 to mitigate this security risk.

CVE
CVE-2026-87785
Severity
CRITICAL
CVSS
9.1
EPSS
N/A
Apache

Original NVD Description

Authentication bypass by spoofing vulnerability in Apache Syncope. When the configured JWKS settings for internal JWT authentication are disclosed (at least protocol and key), an attacker can spoof another user's privileges after completing a successful authentication and obtaining a valid JWT. This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 through 4.0.7, from 4.1.0-M0 through 4.1.2. Users are recommended to upgrade to version 4.0.8 / 4.1.3, which fix this issue.