Identity at Risk: Apache Syncope Patches Critical Login XSS & XXE Flaws
ID: dafe5fa2-ba75-5f04-ac39-c2712c851e9f
STIX ID: report--dafe5fa2-ba75-5f04-ac39-c2712c851e9f
Feed Name: securityonline.info
Threat Score
Apache Software Foundation released security updates for Apache Syncope addressing two vulnerabilities: CVE-2026-23794 (Reflected XSS in the Enduser Login page allowing session hijacking via crafted links) and CVE-2026-23795 (XML External Entity flaw in the Console Keymaster parameters that can leak sensitive data if an administrator is compromised). Users are urged to upgrade to 3.0.16.2 (3.0.x) or 4.0.4 (4.0.x) to patch both issues.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
