Apache · Apache Syncope · CVE-2026-87779
**Name of the Vulnerable Software and Affected Versions**
Apache Syncope versions 3.0.15 through 3.0.16
Apache Syncope versions 4.0.3 through 4.0.7
Apache Syncope versions 4.1.0-M0 through 4.1.2
**Description**
Sensitive information is inserted into log files. When an AES key of a non-standard length (not 16, 24, or 32 bytes) is configured, the system pads the provided value with random characters and logs the resulting key value.
**Recommendations**
Upgrade versions 3.0.15 through 3.0.16 to version 4.0.8.
Upgrade versions 4.0.3 through 4.0.7 to version 4.0.8.
Upgrade versions 4.1.0-M0 through 4.1.2 to version 4.1.3.