Improper Neutralization of Formula Elements in a CSV File in Apache Syncope - CVE-2026-73195
Published: September 15, 2026
Vulnerability details
The vulnerability allows a remote user to execute spreadsheet formulas.
The vulnerability exists due to improper encoding or escaping of output in the CSV export feature when a generated CSV file is opened by a spreadsheet application. A remote user can store a spreadsheet formula payload in one of their own plain attributes to execute spreadsheet formulas.