CVE-2026-23795 | Teknoloji dünyasından en güncel haberleri ve güvenlikle ilgili gelişmeleri takip edin.

Improper Restriction of XML External Entity Reference vulnerability in Apache Syncope Console. An administrator with adequate entitlements to create or edit Key…
Medium CVSS: 4.9

CVE-2026-23795

Improper Restriction of XML External Entity Reference vulnerability in Apache Syncope Console.
An administrator with adequate entitlements to create or edit Keymaster parameters via Console can construct malicious XML text to launch an XXE attack, thereby causing sensitive data leakage occurs.

This issue affects Apache Syncope: from 3.0 through 3.0.15, from 4.0 through 4.0.3.

Users are recommended to upgrade to version 3.0.16 / 4.0.4, which fix this issue.
Vendor
Apache
Product
Syncope
CWE
CWE-611
Yayın Tarihi
2026-02-03 16:16:13
Güncelleme
2026-02-06 14:43:16
Source Identifier
security@apache.org
KEV Date Added
-

Kategoriler

Referanslar