Description

Improper Restriction of XML External Entity Reference vulnerability in Apache Syncope Console. An administrator with adequate entitlements to create or edit Keymaster parameters via Console can construct malicious XML text to launch an XXE attack, thereby causing sensitive data leakage occurs. This issue affects Apache Syncope: from 3.0 through 3.0.15, from 4.0 through 4.0.3. Users are recommended to upgrade to version 3.0.16 / 4.0.4, which fix this issue.

INFO

Published Date :

2026-02-03T15:14:35.448Z

Last Modified :

2026-02-03T16:00:32.112Z

Source :

apache
AFFECTED PRODUCTS

The following products are affected by CVE-2026-23795 vulnerability.

Vendors Products
Apache
  • Syncope
REFERENCES

Here, you will find a curated list of external links that provide in-depth information to CVE-2026-23795.

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact