ThreatCluster

Critical Apache Syncope Vulnerability Allows Session Hijacking

First seen 3 Feb 2026, 14:40 UTC GbhackersCybersecuritynews 95% similarity 30

Article Content

Browse articles
ThreatCluster

A critical XML External Entity (XXE) vulnerability, tracked as CVE-2026-23795, has been disclosed in the Apache Syncope identity management console. This flaw can allow attackers to hijack active user sessions and expose sensitive user data. Multiple versions of the platform are affected and require immediate patching.

ThreatCluster AI

Community

Browse all →

Tracked Entities in This Story