{"api_version":"1","generated_at":"2026-09-14T17:26:27+00:00","cve":"CVE-2026-77883","urls":{"html":"https://cve.report/CVE-2026-77883","api":"https://cve.report/api/cve/CVE-2026-77883.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-77883","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-77883"},"summary":{"title":"Apache Syncope: Information disclosure via one-hop JEXL navigation past the JexlContextBuilder name denylist","description":"Exposure of sensitive information through data queries vulnerability in Apache Syncope.\n\nAn administrator with adequate entitlements for Derived Schemas can create a malicious JEXL expression which allows any administrator with sufficient entitlements for User read to access LinkedAccount's (if present) or Manager's (if defined) sensitive information, possibly including hashed credentials.\n\nThis issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 Through 4.0.7, from 4.1.0-M0 through 4.1.2.\n\nUsers are recommended to upgrade to version 4.0.8 / 4.1.3, which fix this issue.","state":"PUBLISHED","assigner":"apache","published_at":"2026-09-14 13:18:46","updated_at":"2026-09-14 13:18:46"},"problem_types":["CWE-202","CWE-202 CWE-202 Exposure of sensitive information through data queries"],"metrics":[],"references":[{"url":"https://lists.apache.org/thread/oshwdz2k4cl3042y39zq0yl4qkxbd83p","name":"https://lists.apache.org/thread/oshwdz2k4cl3042y39zq0yl4qkxbd83p","refsource":"security@apache.org","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-77883","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-77883","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Apache Software Foundation","product":"Apache Syncope","version":"affected 3.0.0-M0 3.0.16 semver","platforms":[]},{"source":"CNA","vendor":"Apache Software Foundation","product":"Apache Syncope","version":"affected 4.0.0-M0 4.0.7 semver","platforms":[]},{"source":"CNA","vendor":"Apache Software Foundation","product":"Apache Syncope","version":"affected 4.1.0-M0 4.1.2 semver","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[{"source":"CNA","value":"n0mi1k","lang":"en"}],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"collectionURL":"https://repo.maven.apache.org/maven2","defaultStatus":"unaffected","packageName":"org.apache.syncope.core:syncope-core-provisioning-api","packageURL":"pkg:maven/org.apache.syncope.core/syncope-core-provisioning-api","product":"Apache Syncope","vendor":"Apache Software Foundation","versions":[{"lessThanOrEqual":"3.0.16","status":"affected","version":"3.0.0-M0","versionType":"semver"},{"lessThanOrEqual":"4.0.7","status":"affected","version":"4.0.0-M0","versionType":"semver"},{"lessThanOrEqual":"4.1.2","status":"affected","version":"4.1.0-M0","versionType":"semver"}]}],"credits":[{"lang":"en","type":"finder","value":"n0mi1k"}],"descriptions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<p>Exposure of sensitive information through data queries vulnerability in Apache Syncope.</p>An administrator with adequate entitlements for Derived Schemas can create a malicious JEXL expression which allows any administrator with sufficient entitlements for User read to access LinkedAccount's (if present) or Manager's (if defined) sensitive information, possibly including hashed credentials.<br><br>This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 Through 4.0.7, from 4.1.0-M0 through 4.1.2.<br><br>Users are recommended to upgrade to version 4.0.8 / 4.1.3, which fix this issue."}],"value":"Exposure of sensitive information through data queries vulnerability in Apache Syncope.\n\nAn administrator with adequate entitlements for Derived Schemas can create a malicious JEXL expression which allows any administrator with sufficient entitlements for User read to access LinkedAccount's (if present) or Manager's (if defined) sensitive information, possibly including hashed credentials.\n\nThis issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 Through 4.0.7, from 4.1.0-M0 through 4.1.2.\n\nUsers are recommended to upgrade to version 4.0.8 / 4.1.3, which fix this issue."}],"metrics":[{"other":{"content":{"text":"moderate"},"type":"Textual description of severity"},"scenarios":[{"lang":"en","value":"GENERAL"}]}],"problemTypes":[{"descriptions":[{"cweId":"CWE-202","description":"CWE-202 Exposure of sensitive information through data queries","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-09-14T12:30:53.819Z","orgId":"f0158376-9dc2-43b6-827c-5f631a4d8d09","shortName":"apache"},"references":[{"tags":["vendor-advisory"],"url":"https://lists.apache.org/thread/oshwdz2k4cl3042y39zq0yl4qkxbd83p"}],"source":{"discovery":"UNKNOWN"},"title":"Apache Syncope: Information disclosure via one-hop JEXL navigation past the JexlContextBuilder name denylist","x_generator":{"engine":"Vulnogram 1.0.3"}}},"cveMetadata":{"assignerOrgId":"f0158376-9dc2-43b6-827c-5f631a4d8d09","assignerShortName":"apache","cveId":"CVE-2026-77883","datePublished":"2026-09-14T12:30:53.819Z","dateReserved":"2026-08-21T16:15:31.747Z","dateUpdated":"2026-09-14T12:30:53.819Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-09-14 13:18:46","lastModifiedDate":"2026-09-14 13:18:46","problem_types":["CWE-202","CWE-202 CWE-202 Exposure of sensitive information through data queries"],"metrics":[],"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"77883","Ordinal":"1","Title":"Apache Syncope: Information disclosure via one-hop JEXL navigati","CVE":"CVE-2026-77883","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"77883","Ordinal":"1","NoteData":"Exposure of sensitive information through data queries vulnerability in Apache Syncope.\n\nAn administrator with adequate entitlements for Derived Schemas can create a malicious JEXL expression which allows any administrator with sufficient entitlements for User read to access LinkedAccount's (if present) or Manager's (if defined) sensitive information, possibly including hashed credentials.\n\nThis issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 Through 4.0.7, from 4.1.0-M0 through 4.1.2.\n\nUsers are recommended to upgrade to version 4.0.8 / 4.1.3, which fix this issue.","Type":"Description","Title":"Apache Syncope: Information disclosure via one-hop JEXL navigati"}]}}}