CVE-2026-23794: Apache Syncope: Reflected XSS on Enduser Login
Reflected XSS in Apache Syncope's Enduser Login page.
An attacker that tricks a legitimate user into clicking a malicious link and logging in to Syncope Enduser could steal that user's credentials.
This issue affects Apache Syncope: from 3.0 through 3.0.15, from 4.0 through 4.0.3.
Users are recommended to upgrade to version 3.0.16 / 4.0.4, which fix this issue.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-23794?
CVE-2026-23794 has a moderate severity level due to its exploitation potential through reflected cross-site scripting.
How do I fix CVE-2026-23794?
To remediate CVE-2026-23794, upgrade Apache Syncope to version 3.0.16 or 4.0.4 or later.
Which versions of Apache Syncope are affected by CVE-2026-23794?
CVE-2026-23794 affects Apache Syncope versions from 3.0 to 3.0.15 and versions from 4.0 to 4.0.3.
What type of vulnerability is CVE-2026-23794?
CVE-2026-23794 is classified as a reflected cross-site scripting (XSS) vulnerability affecting the Enduser Login page.
What can attackers accomplish by exploiting CVE-2026-23794?
Attackers can steal user credentials by tricking users into clicking malicious links that exploit CVE-2026-23794.