PT-2026-91151 · Apache · Apache Syncope

·

CVE-2026-87779

·

Published

2026-09-14

·

Updated

2026-09-14

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Apache Syncope versions 3.0.15 through 3.0.16 Apache Syncope versions 4.0.3 through 4.0.7 Apache Syncope versions 4.1.0-M0 through 4.1.2
Description Sensitive information is inserted into log files. When an AES key of a non-standard length (not 16, 24, or 32 bytes) is configured, the system pads the provided value with random characters and logs the resulting key value.
Recommendations Upgrade versions 3.0.15 through 3.0.16 to version 4.0.8. Upgrade versions 4.0.3 through 4.0.7 to version 4.0.8. Upgrade versions 4.1.0-M0 through 4.1.2 to version 4.1.3.

Fix

Insertion into Log File

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-87779

Affected Products

Apache Syncope