CVE-2026-78336
Insertion of sensitive information into sent data vulnerability in Apache Syncope. Any authenticated user can query for the list of available OIDC providers configured for SSO with Console and Enduser. The returned payload contains all configuration settings, including client secrets, regardless of the entitlements owned by the caller. This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 through 4.0.7, from 4.1.0-M0 through 4.1.2. Users are recommended to upgrade to version 4.0.8 / 4.1.3, which fix this issue.
Scoring
- Severity
- HIGH
- CVSS base score
- 7.5
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- EPSS probability
- 0.41%
- CWE
- CWE-201
- Published
- 2026-09-14
- Last modified
- 2026-09-14
Affected products
- Apache Software Foundation Apache Syncope
- Apache Software Foundation Apache Syncope
- Apache Software Foundation Apache Syncope
Weakness type
Related vulnerabilities
- CVE-2026-24477 — AnythingLLM has key leak in `systemSettings.js`
- CVE-2026-47717 — FUXA's Unauthenticated Project Data Disclosure Exposes Server-Side Scripts and Device Configurations
- CVE-2026-27934 — Discourse leaks private topic title and post excerpt via user action API endpoint
- CVE-2025-11500 — Credentials exposure in tinycontrol devices
- CVE-2020-37093 — Netis E1+ 1.2.32533 - Unauthenticated WiFi Password Leak
- CVE-2026-27516 — Binardat 10G08-0800GSM Network Switch Plaintext Password Exposure
- CVE-2025-66566 — yawkat LZ4 Java has a possible information leak in Java safe decompressor
- CVE-2026-8924 — trailing dot domain super cookie