CVEFinder.io

CVE-2026-77181

โ›” critical
๐Ÿ” Scan for this CVE
Summary

Incorrect Authorization vulnerability in Apache Syncope. An administrator with ClientApp's update entitlement is unable to perform the related operation, whileย ClientApp's create entitlement is checked both for create and update operations on ClientApp. This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 Through 4.0.7, from 4.1.0-M0 through 4.1.2. Users are recommended to upgrade to version 4.0.8 / 4.1.3, which fix this issue.

CVSS Score
9.8
Critical
EPSS Score
0.5
Exploit Probability
Published Date
2026-09-14
First Seen: 2026-09-16
๐Ÿ“Š Relative Risk Intelligence

This CVE is Very High Risk - more severe than 90.5% of all 357,695 vulnerabilities in our database.

#33,922
Top 10% most severe
Severity Percentile
๐ŸŽฏ CISA SSVC Assessment Updated: Sep 14, 2026
๐Ÿ” Exploitation Status
None
No known exploits
โš™๏ธ Automatable
YES
Can be exploited automatically
๐Ÿ’ฅ Technical Impact
Total
Complete system compromise possible
๐Ÿ† Discovered By
n0mi1k
SSVC data provided by CISA
Last Modified 2026-09-14
CVSS Vector 3.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE IDs (Weakness Types)

๐Ÿ“ฆ Affected Products 0

No affected products information available

๐Ÿ”— References 2