CVE-2026-62183 Details
Description
Improper Privilege Management vulnerability in Apache Syncope. When: * the all-Java user workflow adapter is configured, or * the Flowable user workflow adapter is configured, bearing a BPMN definition not requiring admin approval for user self registration of self update requests the following scenario could happen. A REST API call can allow the user to grant themselves one or more of defined Roles, thus gaining their Entitlements and becoming in fact an administrator; the actual Entitlements gained depend on the Roles that are effectively defined on the specific Syncope deployment. This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 Through 4.0.6, from 4.1.0-M0 through 4.1.1. Users are recommended to upgrade to version 4.0.7 / 4.1.2, which fix this issue.
A vulnerability in Apache Syncope related to improper privilege management has been identified. This issue arises when the all-Java user workflow adapter or the Flowable user workflow adapter is used, with a BPMN definition that does not require administrative approval for user self-registration or self-update requests. Under these conditions, a user can make a REST API call to assign themselves one or more defined roles. This unauthorized role assignment grants them corresponding entitlements, effectively allowing them to assume administrative privileges. The specific entitlements gained depend on the roles defined in the affected Syncope deployment. This vulnerability affects Apache Syncope versions 3.0.0-M0 through 3.0.16, 4.0.0-M0 through 4.0.6, and 4.1.0-M0 through 4.1.1.
Users are advised to upgrade to Apache Syncope versions 4.0.7 or 4.1.2, both of which address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 21, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| http://www.openwall.com/lists/oss-security/2026/07/20/9 | CVE | Mailing ListThird Party Advisory |
| https://lists.apache.org/thread/6r8cngvy43y2yk4jj3w060dt8vx0yzpr | [email protected] | Mailing ListVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-269 | Improper Privilege Management | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| apache syncope | >= 3.0.0, <= 3.0.16 >= 4.0.0, < 4.0.7 >= 4.1.0, < 4.1.2 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 27, 2026 | Initial Analysis | [email protected] |
| Jul 21, 2026 | CVE Modified | CISA-ADP |
| Jul 20, 2026 | CVE Modified | CVE |
| Jul 20, 2026 | New CVE Received | [email protected] |