A vulnerability classified as critical was found in Apache Syncope up to 3.0.16/4.0.6/4.1.1. The impacted element is an unknown function of the component Connectors. Such manipulation leads to server-side request forgery.
This vulnerability is listed as CVE-2026-62418. The attack may be performed from remote. There is no available exploit.