CVE-2026-42797 Details
Description
Exposure of Sensitive Information Through Data Queries vulnerability in Apache Syncope. An administrator with adequate entitlements for Derived Schemas can create a malicious JEXL expression which allows any administrator with sufficient entitlements for User read to access User-related security-sensitive information. This issue affects Apache Syncope: 3.0 through 3.0.16, 4.0 through 4.0.5, 4.1.0. Users are recommended to upgrade to version 4.0.6 / 4.1.1, which fix this issue by further restricting the JEXL expression definition.
A vulnerability allowing exposure of sensitive information through data queries has been identified in Apache Syncope versions 3.0 prior to 3.0.16, 4.0 prior to 4.0.5, and 4.1.0. This issue arises when an administrator with the appropriate entitlements for Derived Schemas creates a malicious JEXL expression. Such an expression can be exploited by any administrator with sufficient entitlements for User read access to retrieve security-sensitive information related to users.
Users are advised to upgrade to Apache Syncope versions 4.0.6 or 4.1.1, both of which address this vulnerability by imposing stricter controls on JEXL expression definitions.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 26, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| http://www.openwall.com/lists/oss-security/2026/05/25/5 | CVE | Mailing ListThird Party Advisory |
| https://lists.apache.org/thread/5y7d277sntyytrmxnx2tfjr9ftcpq1s6 | [email protected] | Mailing ListVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-202 | Exposure of Sensitive Information Through Data Queries | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| apache syncope | >= 3.0.0, <= 3.0.16 >= 4.0.0, < 4.0.6 4.1.0 |
CPE
Remediation
| |
Change History
7 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 24, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 17, 2026 | CVE Modified | [email protected] |
| May 28, 2026 | Initial Analysis | [email protected] |
| May 26, 2026 | CVE Modified | CISA-ADP |
| May 25, 2026 | CVE Modified | CVE |
| May 25, 2026 | New CVE Received | [email protected] |