SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-87802

CRITICAL · CVSS 9.1

Source: NVD + CISA KEV + EPSS · Published 2026-09-14 · Last synced 2026-09-15

CyberRota Analysis

AI-Generated

Apache Syncope versions 3.0.0-M0 to 3.0.16, 4.0.0-M0 to 4.0.7, and 4.1.0-M0 to 4.1.2 are vulnerable due to improper verification of cryptographic signatures, allowing attackers to forge arbitrary JWTs and impersonate any user. This can lead to unauthorized access to services proxied by the SRA, posing a significant security risk. Organizations using affected versions should prioritize upgrading to versions 4.0.8 or 4.1.3 to mitigate this vulnerability.

CVE
CVE-2026-87802
Severity
CRITICAL
CVSS
9.1
EPSS
N/A
Apache

Original NVD Description

Improper verification of cryptographic signature vulnerability in Apache Syncope. When SRA is configured for OAuth 2.0 without JWKS set URI assigned, an attacker can forge arbitrary JWTs to impersonate any user identity and permissions, gaining full access to services proxied by SRA. This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 through 4.0.7, from 4.1.0-M0 through 4.1.2. Users are recommended to upgrade to version 4.0.8 / 4.1.3, which fix this issue.