logo

Apache Syncope Vulnerability Allows Attackers to Hijack Active User Sessions

ID: af24dfea-699b-54c0-83f9-bb6a69a1fe35

STIX ID: report--af24dfea-699b-54c0-83f9-bb6a69a1fe35

Feed Name: GBHackers

Threat Score
50/100

Date Published: 2026-02-03

Date Updated: 2026-04-22

Author: Divya

...
...

Apache Syncope disclosed a moderate-severity XML External Entity (XXE) vulnerability (CVE-2026-23795) in its Console Keymaster parameters that allows authenticated administrators to craft malicious XML to read sensitive files and potentially escalate privileges; versions 3.0–3.0.15 and 4.0–4.0.3 are affected and users should upgrade to 3.0.16 or 4.0.4 and review Keymaster configurations and logs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.