An attacker that tricks a legitimate user into clicking a malicious link and logging in to Syncope Enduser could steal that user's credentials.
This issue affects Apache Syncope: from 3.0 through 3.0.15, from 4.0 through 4.0.3.
Users are recommended to upgrade to version 3.0.16 / 4.0.4, which fix this issue.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-v84m-gfw5-hm2w | Apache Syncope: Reflected XSS on Enduser Login |
Fri, 06 Feb 2026 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:apache:syncope:*:*:*:*:*:*:*:* |
Wed, 04 Feb 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Apache
Apache syncope |
|
| Vendors & Products |
Apache
Apache syncope |
Tue, 03 Feb 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Tue, 03 Feb 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Tue, 03 Feb 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Reflected XSS in Apache Syncope's Enduser Login page. An attacker that tricks a legitimate user into clicking a malicious link and logging in to Syncope Enduser could steal that user's credentials. This issue affects Apache Syncope: from 3.0 through 3.0.15, from 4.0 through 4.0.3. Users are recommended to upgrade to version 3.0.16 / 4.0.4, which fix this issue. | |
| Title | Apache Syncope: Reflected XSS on Enduser Login | |
| Weaknesses | CWE-79 | |
| References |
|
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2026-02-03T16:01:22.030Z
Reserved: 2026-01-16T09:38:02.393Z
Link: CVE-2026-23794
Updated: 2026-02-03T15:19:10.034Z
Status : Analyzed
Published: 2026-02-03T16:16:13.183
Modified: 2026-02-06T14:44:43.847
Link: CVE-2026-23794
No data.
OpenCVE Enrichment
Updated: 2026-04-18T14:15:04Z
Github GHSA