CVE-2026-23794
published 2026-02-03CVE-2026-23794: Reflected XSS in Apache Syncope's Enduser Login page. An attacker that tricks a legitimate user into clicking a malicious link and logging in to Syncope…
PriorityP335medium6.8CVSS 3.1
AVNACLPRLUIRSCCHINAN
EPSS
0.51%
41.7th percentile
Reflected XSS in Apache Syncope's Enduser Login page.
An attacker that tricks a legitimate user into clicking a malicious link and logging in to Syncope Enduser could steal that user's credentials.
This issue affects Apache Syncope: from 3.0 through 3.0.15, from 4.0 through 4.0.3.
Users are recommended to upgrade to version 3.0.16 / 4.0.4, which fix this issue.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | syncope | >= 3.0.0 < 3.0.16 | 3.0.16 |
| apache | syncope | >= 4.0.0 < 4.0.4 | 4.0.4 |
| apache_software_foundation | apache_syncope | 3.0 – 3.0.15 | — |
| apache_software_foundation | apache_syncope | 4.0 – 4.0.3 | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Apache Syncope: Reflected XSS on Enduser Login
ghsa·2026-02-03
CVE-2026-23794 [MEDIUM] CWE-79 Apache Syncope: Reflected XSS on Enduser Login
Apache Syncope: Reflected XSS on Enduser Login
Reflected XSS in Apache Syncope's Enduser Login page.
An attacker that tricks a legitimate user into clicking a malicious link and logging in to Syncope Enduser could steal that user's credentials.
This issue affects Apache Syncope: from 3.0 through 3.0.15, from 4.0 through 4.0.3.
Users are recommended to upgrade to version 3.0.16 / 4.0.4, which fix this issue.
OSV
Apache Syncope: Reflected XSS on Enduser Login
osv·2026-02-03
CVE-2026-23794 [MEDIUM] Apache Syncope: Reflected XSS on Enduser Login
Apache Syncope: Reflected XSS on Enduser Login
Reflected XSS in Apache Syncope's Enduser Login page.
An attacker that tricks a legitimate user into clicking a malicious link and logging in to Syncope Enduser could steal that user's credentials.
This issue affects Apache Syncope: from 3.0 through 3.0.15, from 4.0 through 4.0.3.
Users are recommended to upgrade to version 3.0.16 / 4.0.4, which fix this issue.
No detection rules found.
No public exploits indexed.
Hackernews
⚡ Weekly Recap: Rogue AI Agents, Check Point Exploit, Slopsquatting, ClickFix Lures and More
blogs_hackernews·2026-07-27
CVE-2026-16232 ⚡ Weekly Recap: Rogue AI Agents, Check Point Exploit, Slopsquatting, ClickFix Lures and More
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## ⚡ Weekly Recap: Rogue AI Agents, Check Point Exploit, Slopsquatting, ClickFix Lures and More
Monday starts with the usual promise that everything is under control. Then the logs wake up.
This week, trusted tools crossed lines, old flaws found new work, exposed systems stayed exposed, and attackers kept hiding inside normal-looking services. Nothing looked strange at first. That helped.
That is the mood. Here is the full recap.
## ⚡ Threat of the Week
OpenAI Says Its AI Agent Went Rogue and Targeted Hugging Face - OpenAI disclosed that it lost control of two AI models during a security evaluation that ended in a breach o
Wiz
CVE-2026-23794 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 6.8
CVE-2026-23794 [MEDIUM] CVE-2026-23794 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-23794 :
Java vulnerability analysis and mitigation
Reflected XSS in Apache Syncope's Enduser Login page.
An attacker that tricks a legitimate user into clicking a malicious link and logging in to Syncope Enduser could steal that user's credentials.
This issue affects Apache Syncope: from 3.0 through 3.0.15, from 4.0 through 4.0.3.
Users are recommended to upgrade to version 3.0.16 / 4.0.4, which fix this issue.
Source : NVD
## 6.8
Score
Published February 3, 2026
Severity MEDIUM
CNA Score 6.8
Affected Technologies
Java
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 9.5
Exploitation Probability (EPSS) N/A
Affected packages and libraries
org.apache.syncope.client.idrepo
2026-02-03
Published