CVE-2026-78318: Apache Syncope: Unauthenticated reflected XSS in Console and Enduser
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Apache Syncope.
The notification message, as optionally shown by Console's and Enduser's login pages can be instructed to display HTML tags with unsafe JS inline, via malicious HTTP link generation.
This issue affects Apache Syncope: from 4.0.4 through 4.0.7, from 4.1.0-M0 through 4.1.2.
Users are recommended to upgrade to version 4.0.8 / 4.1.3, which fix this issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache Syncopeto a version that resolves this vulnerability.Fixed in 4.0.8 - Upgrade
Upgrade
Apache Syncopeto a version that resolves this vulnerability.Fixed in 4.1.3
Event History
Frequently Asked Questions
Which deployments are affected?
Apache Syncope versions 4.0.4 through 4.0.7 and 4.1.0-M0 through 4.1.2 are affected. The issue involves notification messages optionally displayed on the Console and Enduser login pages.
Does an attacker need to authenticate to exploit this issue?
No. The issue is described as unauthenticated and can be triggered through malicious HTTP link generation.
What is the recommended remediation?
Upgrade Apache Syncope to version 4.0.8 or 4.1.3, which fix the issue.