CVE-2026-23795Patch(apache / syncope)

MEDIUMCVSS 4.9 · MEDIUM

Exploitation observed; activity peaked at 5 mentions and remains active

Immediate actions

  • Patch apache syncope systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

Improper Restriction of XML External Entity Reference vulnerability in Apache Syncope Console. An administrator with adequate entitlements to create or edit Keymaster parameters via Console can construct malicious XML text to launch an XXE attack, thereby causing sensitive data leakage occurs. This issue affects Apache Syncope: from 3.0 through 3.0.15, from 4.0 through 4.0.3. Users are recommended to upgrade to version 3.0.16 / 4.0.4, which fix this issue.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-611

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • syncope

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 9 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 5 signals
  • Technical details provided in 7 signals
  • General: 2 classified signals
  • Disclosure: 2 classified signals
  • Peaked 3d ago at 5 mentions (2026-02-03); latest day: 1
  • 9 total mentions across 5 days

Affected systems

Vendors
Products
syncope

Deep dive

Activity timeline9 mentions / 5d
01345Mentions · 2026-02-02: 1Mentions · 2026-02-03: 5Mentions · 2026-02-05: 1Mentions · 2026-02-08: 1Mentions · 2026-02-12: 1Active Exploitation · 2026-02-05: 1Patch / Workaround · 2026-02-03: 4Patch / Workaround · 2026-02-05: 1Technical Details · 2026-02-03: 5Technical Details · 2026-02-05: 1Technical Details · 2026-02-12: 102-0202-0302-0502-0802-12
Signal classification4 categories
Patch
444.4%
General
222.2%
Disclosure
222.2%
Active Exploitation
111.1%
Referenced assets13 URLs
Classification over time
DateTotalLabels
2026-02-021
General1
2026-02-035
Disclosure1Patch4
2026-02-051
Active Exploitation1
2026-02-081
General1
2026-02-121
Disclosure1
Full discourse9 posts
  • Open Source Security mailing list@oss_security
    General

    CVE-2026-23794: Apache Syncope: Reflected XSS on Enduser Login https://www.openwall.com/lists/oss-security/2026/02/02/1 CVE-2026-23795: Apache Syncope: Console XXE on Keymaster parameters https://www.openwall.com/lists/oss-security/2026/02/02/2

    Post summary

    The text simply lists two Apache Syncope CVEs with brief descriptors and links to mailing list discussions, lacking detailed technical, exploitation, or mitigation information.

    00030374
    4.4K followersView on X
  • iototsecnews@iototsecnews
    Disclosure

    Apache Syncope の XXE 脆弱性 CVE-2026-23795 が FIX:ユーザー・セッション乗っ取りの恐れ https://iototsecnews.jp/2026/02/04/apache-syncope-vulnerability-let-attackers-hijack-user-sessions/ この問題の原因は、Apache Syncope の管理コンソールが XML 形式のデータを処理する際、外部の情報を参照する機能 (外部エンティティ) を制限せずに許可していたことにあります。具体的には、管理者が設定値を変更する画面などで XML データを入力した際に、たとえば “サーバ内の特定のファイルを読み込め” といった悪意の命令が紛れ込んでいても、そのままシステムが実行してしまう状況が発生します。これが、XML External Entity (XXE) と呼ばれる脆弱性です。この不備により、管理者権限を持つユーザーが本来アクセスできないはずの、機密ファイルや認証トークンを盗み出せる状態になっています。アイデンティティ管理という、組織の鍵を握るシステムにおいて、内部からの情報の漏洩やセッションの乗っ取りのリスクが生じています。ご利用のチームは、ご注意ください。 #Apache #CVE202623795 #Syncope

    Post summary

    The article announces an XXE vulnerability (CVE‑2026‑23795) in Apache Syncope, detailing how it allows attackers to read sensitive files and hijack user sessions, but does not provide PoC, exploit tools, active exploitation reports, or patch information.

    01000131
    483 followersView on X
  • NerdieNews@NewsNerdie
    Active Exploitation

    Today's Top Cybersecurity News – February 05, 2026 1. Critical Metro4Shell RCE Vulnerability Actively Exploited in React Native CLI The Metro4Shell vulnerability (CVE-2025-11953) in the React Native Metro Development Server is being actively exploited by threat actors to execute arbitrary code remotely. This flaw allows attackers to deliver malicious payloads targeting developer systems on Windows and Linux, posing a significant risk to development environments. Sources: Bleepingcomputer, Crowdstrike, Cvefeed, Darkreading, Feedburner, Gbhackers, Infosecurity-Magazine, Krebsonsecurity, Securityaffairs, Securityweek https://thehackernews.com/2026/02/hackers-exploit-metro4shell-rce-flaw-in.html 2. CVE-2026-1341: Critical Missing Authentication in Avation Light Engine Pro Avation Light Engine Pro's configuration and control interface lacks any authentication or access control, allowing unauthorized users to potentially manipulate critical settings. This vulnerability poses a severe risk of unauthorized access and control over affected systems. Sources: Cvefeed, Gbhackers https://cvefeed.io/vuln/detail/CVE-2026-1341 3. Multiple Critical Vulnerabilities in n8n Workflow Automation Platform Allow RCE and Data Exposure Several severe vulnerabilities have been identified in the n8n open source workflow automation platform, including sandbox escapes, arbitrary file write and read, OS command injection, and stored XSS. These flaws allow authenticated users with workflow modification permissions to execute remote code, read sensitive files, and perform cross-site scripting attacks, potentially leading to full system compromise. Patches addressing these issues have been released in recent versions. Sources: Bleepingcomputer, Cvefeed, Feedburner, Infosecurity-Magazine https://cvefeed.io/vuln/detail/CVE-2026-25115 4. Multiple Critical Vulnerabilities Disclosed in Wireless Access Points Including ELECOM and Hikvision Several critical vulnerabilities have been disclosed affecting wireless access points from ELECOM, Hikvision, and WRC models. These include a stack-based buffer overflow, authenticated command execution, and OS command injection, potentially allowing arbitrary code or command execution by attackers. Immediate mitigation and patching are recommended to prevent exploitation. Sources: Cvefeed, Gbhackers https://cvefeed.io/vuln/detail/CVE-2026-24465 5. Critical XXE Vulnerability in Apache Syncope Console Enables Session Hijacking A critical XML External Entity (XXE) vulnerability (CVE-2026-23795) in Apache Syncope's Console component allows authenticated administrators to execute attacks that can extract sensitive data and hijack active user sessions. This flaw affects multiple versions and poses significant risks to identity and access management systems. Sources: Cvefeed, Gbhackers https://gbhackers.com/apache-syncope-vulnerability/ Stay sharp. Stay secure. #NerdieNews #InfoSec #CyberSecurity #TechNews #DataSecurity #CyberThreats

    Post summary

    The roundup highlights several critical vulnerabilities, including an actively exploited Metro4Shell RCE, authentication flaws, and critical bugs in n8n and wireless access points, with patches released and mitigation advised.

    0001068
    54 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-23795 Improper Restriction of XML External Entity Reference vulnerability in Apache Syncope Console. An administrator with adequate entitlements to create or edit Keymaster… https://www.cve.org/CVERecord?id=CVE-2026-23795

    Post summary

    The text references CVE-2026-23795, an XML External Entity (XEE) vulnerability in Apache Syncope Console, but provides no PoC, exploit code, active exploitation, patch, or false‑positive claim. It simply lists the CVE record and basic description.

    00010275
    56.5K followersView on X
  • ThreatCluster@threatcluster
    Patch

    Apache Syncope identity console hit by critical XXE flaw CVE-2026-23795 allowing session hijacking and data exposure. Multiple versions affected, admins urged to patch immediately. #Vulnerability https://threatcluster.io/cluster/critical-apache-syncope-vulnerability-allows-session-hijacki-b20e7986

    Post summary

    Apache Syncope’s CVE-2026-23795 is a critical XXE vulnerability that permits session hijacking and data exposure, and administrators are strongly advised to apply patches immediately.

    0000032
    80 followersView on X
  • ThreatSynop@ThreatSynop
    Patch

    🚨 Apache Syncope Console XXE Flaw (CVE-2026-23795) Enables File Read and Data Exposure A newly disclosed XXE issue in Apache Syncope’s Console Keymaster parameters allows authenticated admin users to supply crafted XML that can read local files and leak sensitive data in IAM environments. Upgrade to Syncope 3.0.16 or 4.0.4 immediately and restrict Console admin access while auditing Keymaster-related configuration changes. 🎯 Target: Global/Identity & Access Management (Apache Syncope) #️⃣ Category: #Vulnerability #BlueTeam 🔗 URL: https://cybersecuritynews.com/apache-syncope-vulnerability-2/

    Post summary

    CVE‑2026‑23795 is an XXE vulnerability in Apache Syncope that lets authenticated admins read local files and expose data. Upgrading to Syncope 3.0.16 or 4.0.4 and limiting admin access is recommended.

    0000067
    192 followersView on X
  • 趣テクノロジー@omomuki_tech
    Patch

    オープンソースのID管理システム「Apache Syncope」において、ユーザーセッションを乗っ取られる可能性のある深刻な脆弱性(CVE-2026-23795)が報告されました。 この問題は「XML外部実体参照(XXE)」と呼ばれる種類の脆弱性です。記事によると、XMLデータの処理における外部エンティティ参照の制限が不適切であったことが原因とされています。 この脆弱性が悪用された場合、管理者権限を持つユーザーが意図せず機密性の高いユーザーデータを漏洩させてしまったり、セッションのセキュリティが侵害されたりする危険性があります。これにより、攻撃者がユーザーセッションをハイジャックする可能性があります。 この脆弱性は複数のバージョンに影響するため、Apache Syncopeを利用している場合は注意が必要です。対策として、提供されている修正パッチを直ちに適用することが強く推奨されています。 #ApacheSyncope #脆弱性 #セキュリティ https://cybersecuritynews.com/apache-syncope-vulnerability-2/

    Post summary

    The article announces CVE‑2026‑23795 as an XXE flaw in Apache Syncope and stresses applying the released patch to mitigate session hijacking risks.

    0000037
    238 followersView on X
  • ThreatSynop@ThreatSynop
    Patch

    🚨 Apache Syncope Console XXE Flaw (CVE-2026-23795) Risks Sensitive Data Leakage for IAM Admins A newly disclosed XXE issue in Apache Syncope’s Console Keymaster parameters lets an authenticated admin craft malicious XML to read sensitive files/internal data and potentially aid session/token compromise in IAM environments. Upgrade immediately to Syncope 3.0.16 or 4.0.4 and audit Keymaster changes while tightening admin privileges and MFA. 🎯 Target: Global/Identity & Access Management (Apache Syncope) #️⃣ Category: #Vulnerability #BlueTeam 🔗 URL: https://cyberpress.org/apache-syncope-vulnerability-2/

    Post summary

    The post discloses a newly found XXE vulnerability in Apache Syncope that could leak sensitive data, and urges administrators to upgrade to specific patch versions and enforce stricter access controls.

    0000051
    192 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-23795 CVE-2026-23795 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-23795

    Post summary

    The text simply lists CVE-2026-23795 and a link to a vulnerability detail page, providing no substantive information about the vulnerability or its exploitation.

    0000086
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appapachesyncope---

Explore more