{"api_version":"1","generated_at":"2026-10-01T01:00:55+00:00","cve":"CVE-2026-78336","urls":{"html":"https://cve.report/CVE-2026-78336","api":"https://cve.report/api/cve/CVE-2026-78336.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-78336","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-78336"},"summary":{"title":"Apache Syncope: OIDCC4UI provider list discloses client secrets to any authenticated user","description":"Insertion of sensitive information into sent data vulnerability in Apache Syncope.\n\n\n\nAny authenticated user can query for the list of available OIDC providers configured for SSO with Console and Enduser. The returned payload contains all configuration settings, including client secrets, regardless of the entitlements owned by the caller.\n\n\n\nThis issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 through 4.0.7, from 4.1.0-M0 through 4.1.2.\n\n\n\nUsers are recommended to upgrade to version 4.0.8 / 4.1.3, which fix this issue.","state":"PUBLISHED","assigner":"apache","published_at":"2026-09-14 13:18:47","updated_at":"2026-09-14 20:58:48"},"problem_types":["CWE-201","CWE-201 CWE-201 Insertion of sensitive information into sent data"],"metrics":[{"version":"3.1","source":"ADP","type":"DECLARED","score":"7.5","severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","data":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":7.5,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"NONE","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","version":"3.1"}},{"version":"3.1","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","score":"7.5","severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"}}],"references":[{"url":"http://www.openwall.com/lists/oss-security/2026/09/14/20","name":"http://www.openwall.com/lists/oss-security/2026/09/14/20","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://lists.apache.org/thread/h399sqmf4wgnfxxpd6x9lm3m672rrsjt","name":"https://lists.apache.org/thread/h399sqmf4wgnfxxpd6x9lm3m672rrsjt","refsource":"security@apache.org","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-78336","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-78336","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Apache Software Foundation","product":"Apache Syncope","version":"affected 3.0.0-M0 3.0.16 semver","platforms":[]},{"source":"CNA","vendor":"Apache Software Foundation","product":"Apache Syncope","version":"affected 4.0.0-M0 4.0.7 semver","platforms":[]},{"source":"CNA","vendor":"Apache Software Foundation","product":"Apache Syncope","version":"affected 4.1.0-M0 4.1.2 semver","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[{"source":"CNA","value":"Moritz Theile","lang":"en"}],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2026","cve_id":"78336","cve":"CVE-2026-78336","epss":"0.004130000","percentile":"0.349200000","score_date":"2026-09-15","updated_at":"2026-09-16 00:11:34"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2026-09-14T18:09:19.843Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"url":"http://www.openwall.com/lists/oss-security/2026/09/14/20"}],"title":"CVE Program Container"},{"metrics":[{"cvssV3_1":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":7.5,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"NONE","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","version":"3.1"}},{"other":{"content":{"id":"CVE-2026-78336","options":[{"Exploitation":"none"},{"Automatable":"yes"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","timestamp":"2026-09-14T19:21:20.096180Z","version":"2.0.3"},"type":"ssvc"}}],"providerMetadata":{"dateUpdated":"2026-09-14T19:21:38.676Z","orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP"},"title":"CISA ADP Vulnrichment"}],"cna":{"affected":[{"collectionURL":"https://repo.maven.apache.org/maven2","defaultStatus":"unaffected","packageName":"org.apache.syncope.ext.oidcc4ui:syncope-ext-oidcc4ui-logic","packageURL":"pkg:maven/org.apache.syncope.ext.oidcc4ui/syncope-ext-oidcc4ui-logic","product":"Apache Syncope","vendor":"Apache Software Foundation","versions":[{"lessThanOrEqual":"3.0.16","status":"affected","version":"3.0.0-M0","versionType":"semver"},{"lessThanOrEqual":"4.0.7","status":"affected","version":"4.0.0-M0","versionType":"semver"},{"lessThanOrEqual":"4.1.2","status":"affected","version":"4.1.0-M0","versionType":"semver"}]}],"credits":[{"lang":"en","type":"finder","value":"Moritz Theile"}],"descriptions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<p>Insertion of sensitive information into sent data vulnerability in Apache Syncope.</p><p>Any authenticated user can query for the list of available OIDC providers configured for SSO with Console and Enduser. The returned payload contains all configuration settings, including client secrets, regardless of the entitlements owned by the caller.</p><p>This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 through 4.0.7, from 4.1.0-M0 through 4.1.2.</p><p>Users are recommended to upgrade to version 4.0.8 / 4.1.3, which fix this issue.</p>"}],"value":"Insertion of sensitive information into sent data vulnerability in Apache Syncope.\n\n\n\nAny authenticated user can query for the list of available OIDC providers configured for SSO with Console and Enduser. The returned payload contains all configuration settings, including client secrets, regardless of the entitlements owned by the caller.\n\n\n\nThis issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 through 4.0.7, from 4.1.0-M0 through 4.1.2.\n\n\n\nUsers are recommended to upgrade to version 4.0.8 / 4.1.3, which fix this issue."}],"metrics":[{"other":{"content":{"text":"moderate"},"type":"Textual description of severity"},"scenarios":[{"lang":"en","value":"GENERAL"}]}],"problemTypes":[{"descriptions":[{"cweId":"CWE-201","description":"CWE-201 Insertion of sensitive information into sent data","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-09-14T12:23:51.971Z","orgId":"f0158376-9dc2-43b6-827c-5f631a4d8d09","shortName":"apache"},"references":[{"tags":["vendor-advisory"],"url":"https://lists.apache.org/thread/h399sqmf4wgnfxxpd6x9lm3m672rrsjt"}],"source":{"discovery":"UNKNOWN"},"title":"Apache Syncope: OIDCC4UI provider list discloses client secrets to any authenticated user","x_generator":{"engine":"Vulnogram 1.0.3"}}},"cveMetadata":{"assignerOrgId":"f0158376-9dc2-43b6-827c-5f631a4d8d09","assignerShortName":"apache","cveId":"CVE-2026-78336","datePublished":"2026-09-14T12:23:51.971Z","dateReserved":"2026-08-24T10:16:14.145Z","dateUpdated":"2026-09-14T19:21:38.676Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-09-14 13:18:47","lastModifiedDate":"2026-09-14 20:58:48","problem_types":["CWE-201","CWE-201 CWE-201 Insertion of sensitive information into sent data"],"metrics":{"cvssMetricV31":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-09-14T19:21:20.096180Z","id":"CVE-2026-78336","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"78336","Ordinal":"1","Title":"Apache Syncope: OIDCC4UI provider list discloses client secrets ","CVE":"CVE-2026-78336","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"78336","Ordinal":"1","NoteData":"Insertion of sensitive information into sent data vulnerability in Apache Syncope.\n\n\n\nAny authenticated user can query for the list of available OIDC providers configured for SSO with Console and Enduser. The returned payload contains all configuration settings, including client secrets, regardless of the entitlements owned by the caller.\n\n\n\nThis issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 through 4.0.7, from 4.1.0-M0 through 4.1.2.\n\n\n\nUsers are recommended to upgrade to version 4.0.8 / 4.1.3, which fix this issue.","Type":"Description","Title":"Apache Syncope: OIDCC4UI provider list discloses client secrets "}]}}}