SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-78330

CRITICAL · CVSS 9.8

Source: NVD + CISA KEV + EPSS · Published 2026-09-14 · Last synced 2026-09-15

CyberRota Analysis

AI-Generated

A critical privilege assignment vulnerability in Apache Syncope allows attackers to escalate their privileges to admin level by exploiting disclosed JWKS settings for internal JWT authentication. This affects versions 3.0.0-M0 through 3.0.16, 4.0.0-M0 through 4.0.7, and 4.1.0-M0 through 4.1.2. Organizations using these versions should prioritize upgrading to 4.0.8 or 4.1.3 to mitigate the risk of unauthorized access.

CVE
CVE-2026-78330
Severity
CRITICAL
CVSS
9.8
EPSS
N/A
Apache

Original NVD Description

Incorrect privilege assignment vulnerability in Apache Syncope. When the configured JWKS settings for internal JWT authentication are disclosed (at least protocol and key), an attacker can obtain admin privileges after completing a successful authentication and obtaining a valid low-privileges JWT. This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 through 4.0.7, from 4.1.0-M0 through 4.1.2. Users are recommended to upgrade to version 4.0.8 / 4.1.3, which fix this issue.