logo

Identity at Risk: Apache Syncope Patches Critical Login XSS & XXE Flaws

ID: dafe5fa2-ba75-5f04-ac39-c2712c851e9f

STIX ID: report--dafe5fa2-ba75-5f04-ac39-c2712c851e9f

Feed Name: securityonline.info

Threat Score
55/100

Date Published: 2026-02-03

Date Updated: 2026-04-23

Author: Ddos

...
...

Apache Software Foundation released security updates for Apache Syncope addressing two vulnerabilities: CVE-2026-23794 (Reflected XSS in the Enduser Login page allowing session hijacking via crafted links) and CVE-2026-23795 (XML External Entity flaw in the Console Keymaster parameters that can leak sensitive data if an administrator is compromised). Users are urged to upgrade to 3.0.16.2 (3.0.x) or 4.0.4 (4.0.x) to patch both issues.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.