# CVE-2026-78336

## Summary

- **CVE ID:** CVE-2026-78336
- **Severity:** HIGH
- **CVSS Score:** 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)
- **CWE:** CWE-201
- **Published:** Sep 14, 2026
- **Last Modified:** Sep 14, 2026

## Description

Insertion of sensitive information into sent data vulnerability in Apache Syncope.



Any authenticated user can query for the list of available OIDC providers configured for SSO with Console and Enduser. The returned payload contains all configuration settings, including client secrets, regardless of the entitlements owned by the caller.



This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 through 4.0.7, from 4.1.0-M0 through 4.1.2.



Users are recommended to upgrade to version 4.0.8 / 4.1.3, which fix this issue.

## Affected Products

- Apache Software Foundation — Apache Syncope (3.0.0-M0)
- Apache Software Foundation — Apache Syncope (4.0.0-M0)
- Apache Software Foundation — Apache Syncope (4.1.0-M0)

## References

- [CNA](https://lists.apache.org/thread/h399sqmf4wgnfxxpd6x9lm3m672rrsjt)
- [CVE](http://www.openwall.com/lists/oss-security/2026/09/14/20)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.41%
- **EPSS Percentile:** 35.2

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-19._