Skip to main content
CRITICAL

CVE-2026-73579

CVSS v3

9.8

CRITICAL

EPSS Score

0.5 %

exploit probability, as of 2026-09-28

CISA KEV

No

known exploited

Exploitation

—

SSVC status

Description

Incorrect Authorization vulnerability in Apache Syncope. Any search requests are transformed into SQL, Neo4J or Elasticsearch / Opensearch queries, depending on the actual deployment configuration. An important component of such transformation is the Realms filter, which ensures that the search results are matching the requester's permissions. For non-recursive search requests it is possible that such Realms filter is rendered as empty, thus voiding any restriction on requester privileges.

Technical details

Published
2026-09-14
Last Modified
2026-09-14

Frequently asked questions

What is CVE-2026-73579?

Incorrect Authorization vulnerability in Apache Syncope. Any search requests are transformed into SQL, Neo4J or Elasticsearch / Opensearch queries, depending on the actual deployment configuration. An important component of such transformation is the Realms filter, which ensures that the search results are matching the requester's permissions. For non-recursive search requests it is possible that such Realms filter is rendered as empty, thus voiding any restriction on requester privileges.

Is CVE-2026-73579 actively exploited?

Active exploitation of CVE-2026-73579 has not been confirmed. Its EPSS score was 0.5% on 2026-09-28, the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2026-73579?

CVE-2026-73579 has a CVSS v3 base score of 9.8 (CRITICAL severity).

Is CVE-2026-73579 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.

No credit card required · 500 free checks/month · Free API key