Description
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Apache Syncope.



The notification message, as optionally shown by Console's and Enduser's login pages can be instructed to display HTML tags with unsafe JS inline, via malicious HTTP link generation.



This issue affects Apache Syncope: from 4.0.4 through 4.0.7, from 4.1.0-M0 through 4.1.2.



Users are recommended to upgrade to version 4.0.8 / 4.1.3, which fix this issue.
Published: 2026-09-14
Score: 6.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Cross‑Site Scripting (Unauthenticated XSS)
Action: Patch immediately
AI Analysis

Impact

Apache Syncope is vulnerable to an unauthenticated reflected XSS flaw that can be triggered by crafting a URL to the Console or Enduser login pages. The application fails to neutralize special characters, allowing an attacker to inject HTML tags and inline JavaScript. When an end‑user visits the malicious URL, the attacker can steal session cookies, deface the site, or execute other client‑side compromise actions.

Affected Systems

Affected versions are 4.0.4 through 4.0.7 and 4.1.0‑M0 through 4.1.2 of Apache Syncope. The flaw exists in the login pages of both the Console and Enduser interfaces.

Risk and Exploitability

The vulnerability allows an attacker to inject custom HTML and JavaScript into the login pages of both the Console and Enduser interfaces by crafting a malicious URL. No authentication is required for the attacker to exploit this flaw. The embedded script can execute in the victim's browser, potentially allowing a third party to acquire session cookies, manipulate the page, or perform other client‑side actions. The EPSS score of <1% indicates that attacks leveraging this weakness are currently unlikely, but the CVSS score of 6.1 reflects a medium severity. This vulnerability is not listed in the CISA KEV catalog.

Generated by OpenCVE AI on September 21, 2026 at 01:18 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Apache Syncope to version 4.0.8 or 4.1.3, the first releases that contain the XSS fix.
  • Restart Syncope services to complete the update.
  • If the patch cannot be applied immediately, block or restrict access to the Console and Enduser login URLs from untrusted networks using a firewall or reverse proxy.

Generated by OpenCVE AI on September 21, 2026 at 01:18 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
References
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 14:15:00 +0000

Type Values Removed Values Added
First Time appeared Apache
Apache syncope
Vendors & Products Apache
Apache syncope

Mon, 14 Sep 2026 12:45:00 +0000

Type Values Removed Values Added
Description Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Apache Syncope. The notification message, as optionally shown by Console's and Enduser's login pages can be instructed to display HTML tags with unsafe JS inline, via malicious HTTP link generation. This issue affects Apache Syncope: from 4.0.4 through 4.0.7, from 4.1.0-M0 through 4.1.2. Users are recommended to upgrade to version 4.0.8 / 4.1.3, which fix this issue.
Title Apache Syncope: Unauthenticated reflected XSS in Console and Enduser
Weaknesses CWE-79
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-09-14T19:17:58.065Z

Reserved: 2026-08-24T08:34:34.116Z

Link: CVE-2026-78318

cve-icon Vulnrichment

Updated: 2026-09-14T18:09:17.279Z

cve-icon NVD

Status : Deferred

Published: 2026-09-14T13:18:47.000

Modified: 2026-09-14T20:58:48.430

Link: CVE-2026-78318

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T01:30:08Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')