Cross-Site Scripting Vulnerability in Apache Syncope by Apache
CVE-2026-78318

Currently unrated

Key Information:

Vendor

Apache

Vendor
CVE Published:
14 September 2026

What is CVE-2026-78318?

A cross-site scripting vulnerability exists in Apache Syncope, stemming from improper handling of input during web page generation. This allows attackers to craft malicious HTTP links that can inject unsafe JavaScript into the application. Affected versions include 4.0.4 through 4.0.7 and 4.1.0-M0 through 4.1.2. It is essential for users to upgrade to versions 4.0.8 and 4.1.3 to mitigate this vulnerability and ensure the security of their applications.

Affected Version(s)

Apache Syncope 4.0.4 <= 4.0.7

Apache Syncope 4.1.0-M0 <= 4.1.2

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Alon Galili
.