CVE-2026-23795 is a vulnerability tracked across 1 threat cluster and 1 intelligence report mention on ThreatCluster. First observed February 3, 2026; most recent activity February 3, 2026.
A critical XML External Entity (XXE) vulnerability, tracked as CVE-2026-23795, has been disclosed in the Apache Syncope identity management console. This flaw can allow attackers to hijack active user sessions and…