Improper XML Handling in Apache Syncope Console
CVE-2026-23795
4.9MEDIUM
What is CVE-2026-23795?
The vulnerability in the Apache Syncope Console allows authenticated administrators to manipulate Keymaster parameters through crafted XML. An attacker can exploit this flaw to launch an XML External Entity (XXE) attack, which may lead to unauthorized exposure of sensitive data. This affects multiple versions of Apache Syncope, specifically versions from 3.0 to 3.0.15 and 4.0 to 4.0.3. It is advisable for users to upgrade to versions 3.0.16 or 4.0.4 to mitigate this security risk.
Affected Version(s)
Apache Syncope 3.0 <= 3.0.15
Apache Syncope 4.0 <= 4.0.3