CVE-2026-87785 PUBLISHED

Apache Syncope: JWT subject spoofing

Assigner: apache
Reserved: 09.09.2026 Published: 14.09.2026 Updated: 14.09.2026

Authentication bypass by spoofing vulnerability in Apache Syncope.

When the configured JWKS settings for internal JWT authentication are disclosed (at least protocol and key), an attacker can spoof another user's privileges after completing a successful authentication and obtaining a valid JWT.

This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 through 4.0.7, from 4.1.0-M0 through 4.1.2.

Users are recommended to upgrade to version 4.0.8 / 4.1.3, which fix this issue.

Product Status

Vendor Apache Software Foundation
Product Apache Syncope
Versions Default: unaffected
  • affected from 3.0.0-M0 to 3.0.16 (incl.)
  • affected from 4.0.0-M0 to 4.0.7 (incl.)
  • affected from 4.1.0-M0 to 4.1.2 (incl.)

Credits

  • Alon Galili finder

References

Problem Types

  • CWE-290 Authentication bypass by spoofing CWE