CVE
CVE-2026-75030
Apache Syncope's GroupLogic.provisionMembers(String, ProvisionAction) schedules a task that mass (de)provisions the members of a group, but resolves the target Group through an unscoped DAO lookup and authorizes the call only against the generic IdRepoEntitlement.TASK_CREATE and TASK_EXECUTE entitlements, without checking that the calling administrator's entitlements actually cover the target group's realm. An administrator who holds only those generic task entitlements -- but lacks group-administration rights over a specific group -- can therefore trigger a mass provision or deprovision of that group's members even though they are not authorized to administer it.
Package Versions Affected
Package Version
patch Availability
No items found.
Automatically patch vulnerabilities without upgrading
Fix Without Upgrading
Detect compatible fix
Apply safe remediation
Fix with a single pull request
CVSS Version
Severity
Base Score
CVSS Version
Score Vector

C
H
U
9.8
-
3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

C
H
U
-

C
H
U
9.8
-
3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Related Resources
No items found.