Skip to main content
Vulnerability Database/CVE-2026-78336

CVE-2026-78336: Apache Syncope Information Disclosure Flaw

CVE-2026-78336 is an information disclosure vulnerability in Apache Syncope that exposes OIDC provider secrets to authenticated users. This article covers technical details, affected versions, and upgrade paths.

Published:

CVE-2026-78336 Overview

CVE-2026-78336 is an information disclosure vulnerability in Apache Syncope, an open-source identity management system. Any authenticated user can query the list of available OpenID Connect (OIDC) providers configured for single sign-on (SSO) with the Console and Enduser applications. The returned payload contains all configuration settings, including client secrets, regardless of the entitlements owned by the caller. The vulnerability is classified under [CWE-201]: Insertion of Sensitive Information Into Sent Data. It affects Apache Syncope versions 3.0.0-M0 through 3.0.16, 4.0.0-M0 through 4.0.7, and 4.1.0-M0 through 4.1.2.

Critical Impact

Authenticated low-privilege users can extract OIDC client secrets from configured SSO providers, enabling downstream identity provider impersonation and potential account takeover across integrated systems.

Affected Products

  • Apache Syncope 3.0.0-M0 through 3.0.16
  • Apache Syncope 4.0.0-M0 through 4.0.7
  • Apache Syncope 4.1.0-M0 through 4.1.2

Discovery Timeline

  • 2026-09-14 - CVE-2026-78336 published to NVD
  • 2026-09-14 - Last updated in NVD database

Technical Details for CVE-2026-78336

Vulnerability Analysis

Apache Syncope exposes an API endpoint that returns the list of configured OIDC providers used for SSO with the Console and Enduser web applications. The endpoint requires authentication but does not filter the returned payload based on the caller's entitlements. As a result, every authenticated user, regardless of role or assigned permissions, receives the complete provider configuration.

The returned data includes the OIDC clientSecret field alongside other provider parameters such as issuer URLs, client IDs, and scope definitions. Client secrets are shared credentials used to authenticate the Syncope deployment to the upstream identity provider during the OIDC authorization code exchange. Exposure of these secrets breaks the trust boundary between Syncope and the identity provider.

Root Cause

The root cause is missing authorization enforcement on the OIDC provider listing endpoint. The endpoint returns the raw provider configuration object rather than a filtered projection that omits sensitive fields for callers without administrative entitlements. This is a broken access control pattern paired with insufficient response sanitization.

Attack Vector

An attacker requires only valid authenticated credentials to any Syncope account, including standard Enduser accounts with no elevated privileges. The attacker issues a request to the OIDC providers endpoint and parses the JSON response to extract clientSecret values. With the client ID and client secret pair, the attacker can then interact with the upstream OIDC identity provider as if they were the Syncope deployment, enabling token requests, potential authorization code interception, and impersonation attacks against SSO-integrated applications. No user interaction is required. Refer to the Apache Mailing List Thread and the OpenWall OSS Security Update for details.

Detection Methods for CVE-2026-78336

Indicators of Compromise

  • Unexpected authenticated requests to the Syncope OIDC providers listing endpoint from non-administrative user sessions.
  • OIDC token requests to the upstream identity provider originating from IP addresses or user agents not associated with the Syncope deployment.
  • Sudden surge in read operations against SSO configuration APIs by low-privileged accounts.

Detection Strategies

  • Audit Syncope access logs for requests to OIDC provider configuration endpoints and correlate the caller's role against expected administrative entitlements.
  • Enable request/response logging at the reverse proxy layer to identify responses containing clientSecret keys returned to non-administrative sessions.
  • Review upstream OIDC identity provider logs for anomalous client authentication events or token issuance patterns.

Monitoring Recommendations

  • Alert on any HTTP 200 responses from OIDC provider listing endpoints served to accounts lacking IDP_READ or equivalent administrative entitlements.
  • Monitor for repeated enumeration of the SSO configuration API by a single authenticated session.
  • Rotate and monitor OIDC client secrets on a shortened cadence until affected deployments are patched.

How to Mitigate CVE-2026-78336

Immediate Actions Required

  • Upgrade Apache Syncope to version 4.0.8 or 4.1.3, which contain the fix for CVE-2026-78336.
  • Rotate all OIDC client secrets for providers configured in affected Syncope deployments after patching.
  • Review Syncope user accounts and revoke unnecessary authenticated access to reduce the exposed attack surface.
  • Audit upstream OIDC identity provider logs for evidence of credential misuse dating back to when the vulnerable version was deployed.

Patch Information

The Apache Syncope project has released fixed versions 4.0.8 and 4.1.3. Users of the 3.0.x branch should evaluate migration paths, as the advisory identifies 3.0.0-M0 through 3.0.16 as affected without listing a corresponding 3.0.x fix. Consult the Apache Mailing List Thread for the official release announcement.

Workarounds

  • Restrict network access to Syncope Console and Enduser endpoints to trusted networks until upgrades are applied.
  • Enforce strict account provisioning and disable self-registration to limit the pool of authenticated users who can invoke the vulnerable endpoint.
  • Place a reverse proxy or web application firewall in front of Syncope to block requests to OIDC provider listing endpoints from non-administrative sessions.

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.