CVE-2026-77883
Exposure of sensitive information through data queries vulnerability in Apache Syncope. An administrator with adequate entitlements for Derived Schemas can create a malicious JEXL expression which allows any administrator with sufficient entitlements for User read to access LinkedAccount's (if present) or Manager's (if defined) sensitive information, possibly including hashed credentials. This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 Through 4.0.7, from 4.1.0-M0 through 4.1.2. Users are recommended to upgrade to version 4.0.8 / 4.1.3, which fix this issue.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 4.9
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
- EPSS probability
- 0.38%
- CWE
- CWE-202
- Published
- 2026-09-14
- Last modified
- 2026-09-14
Affected products
- Apache Software Foundation Apache Syncope
- Apache Software Foundation Apache Syncope
- Apache Software Foundation Apache Syncope
Weakness type
Related vulnerabilities
- CVE-2021-32743 — Passwords used to access external services inadvertently exposed through API
- CVE-2025-25205 — Remote Authentication-Bypass can lead to server crash or limited information disclosure due to faulty pattern matching
- CVE-2026-33530 — InvenTree Vulnerable to ORM Filter Injection
- CVE-2025-69200 — phpMyFAQ has unauthenticated config backup download via /api/setup/backup
- CVE-2025-36575 — Dell Wyse Management Suite, versions prior to WMS 5.2, contain an Exposure of Sensitive Information Through Data Queries
- CVE-2025-29981 — Dell Wyse Management Suite, versions prior to WMS 5.1, contains an Exposure of Sensitive Information Through Data Querie
- CVE-2023-1625 — Information leak in api
- CVE-2026-16520 — Improper input validation and Exposure of sensitive information through data queries vulnerability in Genians Genian NAC