Apache Syncope JWT authentication bypass via JWKS spoofing
Authentication bypass by spoofing in Apache Syncope. If an attacker obtains the JWKS protocol and key used for internal JWT authentication, they can forge valid tokens and bypass authentication.
- Vendor
- Apache
- Product
- Syncope
- CVSS
- 9.1
- EPSS (exploit probability)
- 0.5%
- Status
- patched
- Published
Apache Syncope uses JWKS (JSON Web Key Sets) for internal JWT authentication. When the configured JWKS settings, at minimum the protocol and key, are accessible to an attacker, that attacker can construct tokens that pass Syncope’s authentication checks.
The flaw is most relevant in deployments where Syncope’s internal APIs are exposed to broader network segments, or where the JWKS configuration is not restricted to internal access only.
The Apache Software Foundation released a patch in September 2026. See the advisory on the Apache security mailing list and the related Apache Syncope patch article for the full patch priority order.
