SEPTEMBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-62418

HIGH · CVSS 8.1 EPSS 0.30%

Source: NVD + CISA KEV + EPSS · Published 2026-07-20 · Last synced 2026-08-19

CyberRota Analysis

AI-Generated

Apache Syncope versions 3.0.0-M0 to 3.0.16, 4.0.0-M0 to 4.0.6, and 4.1.0-M0 to 4.1.1 are vulnerable to a low-privileged authenticated Server-Side Request Forgery (SSRF) attack, which could allow attackers to manipulate server requests and potentially access sensitive data. Organizations using these affected versions should prioritize upgrading to versions 4.0.7 or 4.1.2 to mitigate the risk of exploitation.

CVE
CVE-2026-62418
Severity
HIGH
CVSS
8.1
EPSS
0.30%
Apache

Original NVD Description

Low-privileged authenticated Server-Side Request Forgery (SSRF) vulnerability in Apache Syncope via Connectors and Resources check. This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 Through 4.0.6, from 4.1.0-M0 through 4.1.1. Users are recommended to upgrade to version 4.0.7 / 4.1.2, which fix this issue.

Related CVEs

Other vulnerabilities affecting the same vendor(s)