Apache Syncope SRA allows JWT forgery without JWKS URI
Improper cryptographic signature verification in Apache Syncope SRA. When SRA is configured for OAuth 2.0 without a JWKS URI assigned, an attacker can forge arbitrary JWTs and impersonate any user in the system.
- Vendor
- Apache
- Product
- Syncope SRA
- CVSS
- 9.1
- EPSS (exploit probability)
- 0.3%
- Status
- patched
- Published
Apache Syncope’s SRA (Security Request Analyzer) component handles OAuth 2.0 and SAML/OIDC relay functions. When SRA is configured for OAuth 2.0 without a JWKS set URI assigned, it does not properly verify JWT signatures. An attacker can forge arbitrary JWTs and impersonate any user in the Syncope deployment.
This is the highest-priority item in the September 2026 Syncope patch batch. Verify whether your SRA configuration has a JWKS URI set before patching, so you can assess whether the exposure window was open.
After patching, review any audit logs for SRA authentication events that may indicate unauthorized token use. See the full advisory and the Apache Syncope patch article.
