CVE
CVE-2026-73668
Incorrect Authorization vulnerability in Apache Syncope. ConnectorLogic.readByResource(resourceName, lang) resolves an External Resource by name and returns its Connector's full configuration by calling connectorManager.getConnector(resource).getConnInstance() directly, without routing through the realm-scoped ConnInstanceDAO.authFind(key) lookup that the sibling read(key) method uses. An administrator holding the CONNECTOR_READ entitlement in one Realm can therefore call the REST endpoint mapped to readByResource, name an External Resource whose Connector is scoped to a different Realm, and receive that Connector's full configuration -- confidential/credential properties included in cleartext -- letting them duplicate the Connector into a Realm they administer. This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 through 4.0.7, from 4.1.0-M0 through 4.1.2. Users are recommended to upgrade to version 4.0.8 / 4.1.3, which fix this issue.
Package Versions Affected
Package Version
patch Availability
No items found.
Automatically patch vulnerabilities without upgrading
Fix Without Upgrading
Detect compatible fix
Apply safe remediation
Fix with a single pull request
CVSS Version
Severity
Base Score
CVSS Version
Score Vector

C
H
U
9.8
-
3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

C
H
U
-

C
H
U
9.8
-
3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Related Resources
No items found.