{"id":"CVE-2026-42797","aliases":["GHSA-vr35-jm2f-8wg2"],"url":"https://o3.security/vulnerability/CVE-2026-42797","summary":"Apache Syncope: JexlContextBuilder Information Disclosure","details":"Exposure of Sensitive Information Through Data Queries vulnerability in Apache Syncope.\n\nAn administrator with adequate entitlements for Derived Schemas can create a malicious JEXL expression which allows any administrator with sufficient entitlements for User read to access User-related security-sensitive information.\n\nThis issue affects Apache Syncope: 3.0 through 3.0.16, 4.0 through 4.0.5, 4.1.0.\n\nUsers are recommended to upgrade to version 4.0.6 / 4.1.1, which fix this issue by further restricting the JEXL expression definition.","published":"2026-05-25T15:00:55.670Z","modified":"2026-08-12T03:51:39.996653264Z","cvss":{"score":4.9,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N"},"epss":{"score":0.00437,"percentile":0.36203,"asOf":"2026-08-13"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Maven","name":"org.apache.syncope.core:syncope-core-provisioning-api","fixedVersion":null},{"ecosystem":"Maven","name":"org.apache.syncope.core:syncope-core-provisioning-api","fixedVersion":"4.0.6"},{"ecosystem":"Maven","name":"org.apache.syncope.core:syncope-core-provisioning-api","fixedVersion":"4.1.1"}],"fix":null,"references":[{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2026/05/25/5"},{"type":"WEB","url":"https://repo.maven.apache.org/maven2"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/42xxx/CVE-2026-42797.json"},{"type":"ADVISORY","url":"https://lists.apache.org/thread/5y7d277sntyytrmxnx2tfjr9ftcpq1s6"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-42797"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:39.996653264Z"}}