Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-87802

Опубликовано: 14 сент. 2026
Источник: nvd
CVSS3: 9.1
EPSS Низкий

Описание

Improper verification of cryptographic signature vulnerability in Apache Syncope.

When SRA is configured for OAuth 2.0 without JWKS set URI assigned, an attacker can forge arbitrary JWTs to impersonate any user identity and permissions, gaining full access to services proxied by SRA.

This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 through 4.0.7, from 4.1.0-M0 through 4.1.2.

Users are recommended to upgrade to version 4.0.8 / 4.1.3, which fix this issue.

EPSS

Процентиль: 18%
0.00257
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-347

Связанные уязвимости

CVSS3: 9.1
github
10 дней назад

Improper verification of cryptographic signature vulnerability in Apache Syncope. When SRA is configured for OAuth 2.0 without JWKS set URI assigned, an attacker can forge arbitrary JWTs to impersonate any user identity and permissions, gaining full access to services proxied by SRA. This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 through 4.0.7, from 4.1.0-M0 through 4.1.2. Users are recommended to upgrade to version 4.0.8 / 4.1.3, which fix this issue.

EPSS

Процентиль: 18%
0.00257
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-347