Exposure of Sensitive Information Through Data Queries vulnerability in Apache Syncope.
An administrator with adequate entitlements for Derived Schemas can create a malicious JEXL expression which allows any administrator with sufficient entitlements for User read to access User-related security-sensitive information.
This issue affects Apache Syncope: 3.0 through 3.0.16, 4.0 through 4.0.5, 4.1.0.
Users are recommended to upgrade to version 4.0.6 / 4.1.1, which fix this issue by further restricting the JEXL expression definition.
Metrics
Affected Vendors & Products
References
History
Thu, 28 May 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:apache:syncope:*:*:*:*:*:*:*:* cpe:2.3:a:apache:syncope:4.1.0:*:*:*:*:*:*:* |
Tue, 26 May 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Tue, 26 May 2026 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Mon, 25 May 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Apache
Apache syncope |
|
| Vendors & Products |
Apache
Apache syncope |
Mon, 25 May 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Exposure of Sensitive Information Through Data Queries vulnerability in Apache Syncope. An administrator with adequate entitlements for Derived Schemas can create a malicious JEXL expression which allows any administrator with sufficient entitlements for User read to access User-related security-sensitive information. This issue affects Apache Syncope: 3.0 through 3.0.16, 4.0 through 4.0.5, 4.1.0. Users are recommended to upgrade to version 4.0.6 / 4.1.1, which fix this issue by further restricting the JEXL expression definition. | |
| Title | Apache Syncope: JexlContextBuilder Information Disclosure | |
| Weaknesses | CWE-202 | |
| References |
|
Status: PUBLISHED
Assigner: apache
Published: 2026-05-25T15:00:55.670Z
Updated: 2026-05-26T20:06:31.884Z
Reserved: 2026-04-30T06:10:34.810Z
Link: CVE-2026-42797
Updated: 2026-05-25T20:30:25.603Z
Status : Analyzed
Published: 2026-05-25T16:16:20.390
Modified: 2026-05-28T20:19:06.687
Link: CVE-2026-42797
No data.