SEPTEMBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-62183

CRITICAL · CVSS 9.8 EPSS 0.41%

Source: NVD + CISA KEV + EPSS · Published 2026-07-20 · Last synced 2026-08-19

CyberRota Analysis

AI-Generated

Apache Syncope versions 3.0.0-M0 to 4.1.1 are vulnerable to improper privilege management, allowing users to exploit REST API calls to self-assign administrative roles without proper authorization. This critical vulnerability can lead to unauthorized access and control over the system, potentially compromising sensitive data and operations. Organizations using affected versions should prioritize upgrading to versions 4.0.7 or 4.1.2 to mitigate this risk.

CVE
CVE-2026-62183
Severity
CRITICAL
CVSS
9.8
EPSS
0.41%
Apache Java

Original NVD Description

Improper Privilege Management vulnerability in Apache Syncope. When: * the all-Java user workflow adapter is configured, or * the Flowable user workflow adapter is configured, bearing a BPMN definition not requiring admin approval for user self registration of self update requests the following scenario could happen. A REST API call can allow the user to grant themselves one or more of defined Roles, thus gaining their Entitlements and becoming in fact an administrator; the actual Entitlements gained depend on the Roles that are effectively defined on the specific Syncope deployment. This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 Through 4.0.6, from 4.1.0-M0 through 4.1.1. Users are recommended to upgrade to version 4.0.7 / 4.1.2, which fix this issue.

Related CVEs

Other vulnerabilities affecting the same vendor(s)