Cross-site scripting in Apache Syncope - CVE-2026-78318

 

Cross-site scripting in Apache Syncope - CVE-2026-78318

Published: September 15, 2026


Vulnerability identifier: #VU149991
CSH Severity: Medium
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
CVE-ID: CVE-2026-78318
CWE-ID: CWE-79
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary JavaScript in the victim's browser.

The vulnerability exists due to improper neutralization of input during web page generation in the notification message displayed on Console and Enduser login pages when processing a malicious HTTP link. A remote attacker can generate a malicious HTTP link to execute arbitrary JavaScript in the victim's browser.

User interaction is required to open the malicious link.


Affected software

Apache Syncope

How to mitigate CVE-2026-78318

Install security update from vendor's website.

Apache Syncope - addressed in versions 4.0.8, 4.1.3

External References

Related Security Bulletins