{"api_version":"1","generated_at":"2026-07-21T07:24:16+00:00","cve":"CVE-2026-62183","urls":{"html":"https://cve.report/CVE-2026-62183","api":"https://cve.report/api/cve/CVE-2026-62183.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-62183","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-62183"},"summary":{"title":"Apache Syncope: User self-service privilege escalation","description":"Improper Privilege Management vulnerability in Apache Syncope.\n\nWhen:\n\n* the all-Java user workflow adapter is configured, or\n* the Flowable user workflow adapter is configured, bearing a BPMN definition not requiring admin approval for user self registration of self update requests\n\nthe following scenario could happen.\nA REST API call can allow the user to grant themselves one or more of defined Roles, thus gaining their Entitlements and becoming in fact an administrator; the actual Entitlements gained depend on the Roles that are effectively defined on the specific Syncope deployment.\n\n\nThis issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 Through 4.0.6, from 4.1.0-M0 through 4.1.1.\n\nUsers are recommended to upgrade to version 4.0.7 / 4.1.2, which fix this issue.","state":"PUBLISHED","assigner":"apache","published_at":"2026-07-20 15:16:44","updated_at":"2026-07-20 19:17:28"},"problem_types":["CWE-269","CWE-269 CWE-269 Improper Privilege Management"],"metrics":[],"references":[{"url":"https://lists.apache.org/thread/6r8cngvy43y2yk4jj3w060dt8vx0yzpr","name":"https://lists.apache.org/thread/6r8cngvy43y2yk4jj3w060dt8vx0yzpr","refsource":"security@apache.org","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"http://www.openwall.com/lists/oss-security/2026/07/20/9","name":"http://www.openwall.com/lists/oss-security/2026/07/20/9","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-62183","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-62183","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Apache Software Foundation","product":"Apache Syncope","version":"affected 3.0.0-M0 3.0.16 semver","platforms":[]},{"source":"CNA","vendor":"Apache Software Foundation","product":"Apache Syncope","version":"affected 4.0.0-M0 4.0.6 semver","platforms":[]},{"source":"CNA","vendor":"Apache Software Foundation","product":"Apache Syncope","version":"affected 4.1.0-M0 4.1.1 semver","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[{"source":"CNA","value":"Nic Jones","lang":"en"},{"source":"CNA","value":"elin kai","lang":"en"}],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2026-07-20T18:38:18.526Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"url":"http://www.openwall.com/lists/oss-security/2026/07/20/9"}],"title":"CVE Program Container"}],"cna":{"affected":[{"collectionURL":"https://repo.maven.apache.org/maven2","defaultStatus":"unaffected","packageName":"org.apache.syncope.core:syncope-core-workflow-java","product":"Apache Syncope","vendor":"Apache Software Foundation","versions":[{"lessThanOrEqual":"3.0.16","status":"affected","version":"3.0.0-M0","versionType":"semver"},{"lessThanOrEqual":"4.0.6","status":"affected","version":"4.0.0-M0","versionType":"semver"},{"lessThanOrEqual":"4.1.1","status":"affected","version":"4.1.0-M0","versionType":"semver"}]}],"credits":[{"lang":"en","type":"finder","value":"Nic Jones"},{"lang":"en","type":"finder","value":"elin kai"}],"descriptions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<p>Improper Privilege Management vulnerability in Apache Syncope.<br><br>When:<br><br>* the all-Java user workflow adapter is configured, or<br>* the Flowable user workflow adapter is configured, bearing a BPMN definition not requiring admin approval for user self registration of self update requests</p>the following scenario could happen.<br><div>A REST API call can allow the user to grant themselves one or more of defined Roles, thus gaining their Entitlements and becoming in fact an administrator; the actual Entitlements gained depend on the Roles that are effectively defined on the specific Syncope deployment.</div><div><br>This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 Through 4.0.6, from 4.1.0-M0 through 4.1.1.<br><br>Users are recommended to upgrade to version 4.0.7 / 4.1.2, which fix this issue.<br></div>"}],"value":"Improper Privilege Management vulnerability in Apache Syncope.\n\nWhen:\n\n* the all-Java user workflow adapter is configured, or\n* the Flowable user workflow adapter is configured, bearing a BPMN definition not requiring admin approval for user self registration of self update requests\n\nthe following scenario could happen.\nA REST API call can allow the user to grant themselves one or more of defined Roles, thus gaining their Entitlements and becoming in fact an administrator; the actual Entitlements gained depend on the Roles that are effectively defined on the specific Syncope deployment.\n\n\nThis issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 Through 4.0.6, from 4.1.0-M0 through 4.1.1.\n\nUsers are recommended to upgrade to version 4.0.7 / 4.1.2, which fix this issue."}],"metrics":[{"other":{"content":{"text":"important"},"type":"Textual description of severity"}}],"problemTypes":[{"descriptions":[{"cweId":"CWE-269","description":"CWE-269 Improper Privilege Management","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-07-20T14:23:20.294Z","orgId":"f0158376-9dc2-43b6-827c-5f631a4d8d09","shortName":"apache"},"references":[{"tags":["vendor-advisory"],"url":"https://lists.apache.org/thread/6r8cngvy43y2yk4jj3w060dt8vx0yzpr"}],"source":{"discovery":"UNKNOWN"},"title":"Apache Syncope: User self-service privilege escalation","x_generator":{"engine":"Vulnogram 0.2.0"}}},"cveMetadata":{"assignerOrgId":"f0158376-9dc2-43b6-827c-5f631a4d8d09","assignerShortName":"apache","cveId":"CVE-2026-62183","datePublished":"2026-07-20T14:23:20.294Z","dateReserved":"2026-07-13T14:30:10.801Z","dateUpdated":"2026-07-20T18:38:18.526Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-07-20 15:16:44","lastModifiedDate":"2026-07-20 19:17:28","problem_types":["CWE-269","CWE-269 CWE-269 Improper Privilege Management"],"metrics":[],"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"62183","Ordinal":"1","Title":"Apache Syncope: User self-service privilege escalation","CVE":"CVE-2026-62183","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"62183","Ordinal":"1","NoteData":"Improper Privilege Management vulnerability in Apache Syncope.\n\nWhen:\n\n* the all-Java user workflow adapter is configured, or\n* the Flowable user workflow adapter is configured, bearing a BPMN definition not requiring admin approval for user self registration of self update requests\n\nthe following scenario could happen.\nA REST API call can allow the user to grant themselves one or more of defined Roles, thus gaining their Entitlements and becoming in fact an administrator; the actual Entitlements gained depend on the Roles that are effectively defined on the specific Syncope deployment.\n\n\nThis issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 Through 4.0.6, from 4.1.0-M0 through 4.1.1.\n\nUsers are recommended to upgrade to version 4.0.7 / 4.1.2, which fix this issue.","Type":"Description","Title":"Apache Syncope: User self-service privilege escalation"}]}}}