Apparently, some service needed to be restarted, because the problem went away after a reboot. Perhaps policykit?
Anyway, for future reference, I'm not on the sudo group and I found nothing interesting on changelogs. Something (I guess pkexec) asks for the root password (not the user's password) before allowing synaptic to run and doesn't care whether the user is allowed to sudo (my user is allowed). -- Bruno Schneider