Apache Syncope Vulnerability Allows Attackers to Hijack Active User Sessions
ID: af24dfea-699b-54c0-83f9-bb6a69a1fe35
STIX ID: report--af24dfea-699b-54c0-83f9-bb6a69a1fe35
Feed Name: GBHackers
Threat Score
Apache Syncope disclosed a moderate-severity XML External Entity (XXE) vulnerability (CVE-2026-23795) in its Console Keymaster parameters that allows authenticated administrators to craft malicious XML to read sensitive files and potentially escalate privileges; versions 3.0–3.0.15 and 4.0–4.0.3 are affected and users should upgrade to 3.0.16 or 4.0.4 and review Keymaster configurations and logs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
