CVE-2026-87802 PUBLISHED

Apache Syncope: SRA OAuth2 JWT signature verification bypass

Assigner: apache
Reserved: 09.09.2026 Published: 14.09.2026 Updated: 14.09.2026

Improper verification of cryptographic signature vulnerability in Apache Syncope.

When SRA is configured for OAuth 2.0 without JWKS set URI assigned, an attacker can forge arbitrary JWTs to impersonate any user identity and permissions, gaining full access to services proxied by SRA.

This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 through 4.0.7, from 4.1.0-M0 through 4.1.2.

Users are recommended to upgrade to version 4.0.8 / 4.1.3, which fix this issue.

Product Status

Vendor Apache Software Foundation
Product Apache Syncope
Versions Default: unaffected
  • affected from 3.0.0-M0 to 3.0.16 (incl.)
  • affected from 4.0.0-M0 to 4.0.7 (incl.)
  • affected from 4.1.0-M0 to 4.1.2 (incl.)

Credits

  • MopMonk AI finder

References

Problem Types

  • CWE-347 Improper verification of cryptographic signature CWE