6.8
/ 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:N/A:N
Description
Reflected XSS in Apache Syncope's Enduser Login page.
An attacker that tricks a legitimate user into clicking a malicious link and logging in to Syncope Enduser could steal that user's credentials.
This issue affects Apache Syncope: from 3.0 through 3.0.15, from 4.0 through 4.0.3.
Users are recommended to upgrade to version 3.0.16 / 4.0.4, which fix this issue.
An attacker that tricks a legitimate user into clicking a malicious link and logging in to Syncope Enduser could steal that user's credentials.
This issue affects Apache Syncope: from 3.0 through 3.0.15, from 4.0 through 4.0.3.
Users are recommended to upgrade to version 3.0.16 / 4.0.4, which fix this issue.
Basic Information
ID
CVE-2026-23794
Source
apache
Published
Feb 3, 2026 at 15:15
Modified
Feb 3, 2026 at 16:01
Affected Product
Vendor
Apache Software Foundation
Product
Apache Syncope
Version
3.0
Affected Versions
Apache Software Foundation Apache Syncope 3.0
Apache Software Foundation Apache Syncope 4.0
Apache Software Foundation Apache Syncope 4.0