https://seclists.org/oss-sec/2026/q1/138: CVE-2026-23794: Apache Syncope: flected XSS on Enduser Login
Published Feb 2, 2026
·Updated
Affected Software
2 affected components
Apache Syncope>=3.0<3.0.15, >=4.0<4.0.3
maven/org.apache.syncope.client.idrepo/syncope-client-idrepo-common-ui>=3.0<3.0.15, >=4.0<4.0.3
Frequently Asked Questions
1
What is the severity of CVE-2026-23794?
The severity of CVE-2026-23794 is classified as important.
2
Which versions of Apache Syncope are affected by CVE-2026-23794?
CVE-2026-23794 affects Apache Syncope versions 3.0 through 3.0.15 and 4.0 through 4.0.3.
3
What type of vulnerability is CVE-2026-23794?
CVE-2026-23794 is a reflected XSS (Cross-Site Scripting) vulnerability.
4
How do I fix CVE-2026-23794?
To fix CVE-2026-23794, update Apache Syncope to a patched version beyond 3.0.15 or 4.0.3.
5
What components of Apache Syncope are affected by CVE-2026-23794?
CVE-2026-23794 affects the org.apache.syncope.client.idrepo:syncope-client-idrepo-common-ui component.