CVE-2026-77181
โ criticalSummary
Incorrect Authorization vulnerability in Apache Syncope. An administrator with ClientApp's update entitlement is unable to perform the related operation, whileย ClientApp's create entitlement is checked both for create and update operations on ClientApp. This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 Through 4.0.7, from 4.1.0-M0 through 4.1.2. Users are recommended to upgrade to version 4.0.8 / 4.1.3, which fix this issue.
CVSS Score
9.8
Critical
EPSS Score
0.5
Exploit Probability
Published Date
2026-09-14
First Seen: 2026-09-16
๐ Relative Risk Intelligence
This CVE is Very High Risk - more severe than 90.5% of all 357,695 vulnerabilities in our database.
#33,922
Top 10% most severe
Severity Percentile
๐ฏ CISA SSVC Assessment Updated: Sep 14, 2026
๐ Exploitation Status
None
No known exploits
โ๏ธ Automatable
YES
Can be exploited automatically
๐ฅ Technical Impact
Total
Complete system compromise possible
๐ Discovered By
n0mi1k
SSVC data provided by
CISA
Last Modified
2026-09-14
Source
NVD ๐
CVSS Vector 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE IDs (Weakness Types)