https://seclists.org/oss-sec/2026/q1/139: CVE-2026-23795: Apache Syncope: Console XXE on Keymaster parameters
Published Feb 2, 2026
·Updated
Affected Software
1 affected component
Apache Syncope>=3.0<=3.0.15, >=4.0<=4.0.3
Frequently Asked Questions
1
What is the severity of CVE-2026-23795?
The severity of CVE-2026-23795 is categorized as moderate.
2
Which versions of Apache Syncope are affected by CVE-2026-23795?
Apache Syncope versions 3.0 through 3.0.15 and 4.0 through 4.0.3 are affected by CVE-2026-23795.
3
What type of vulnerability is CVE-2026-23795?
CVE-2026-23795 is classified as an improper restriction of XML external entity reference vulnerability.
4
How do I fix CVE-2026-23795?
To fix CVE-2026-23795, update Apache Syncope to a version that is not vulnerable, such as 3.0.16 or 4.0.4 and later.
5
What is the impact of exploiting CVE-2026-23795?
Exploiting CVE-2026-23795 may allow attackers to read arbitrary files on the server via XML external entity injection.