Cross-site scripting in Apache Syncope - CVE-2026-78318
Published: September 15, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary JavaScript in the victim's browser.
The vulnerability exists due to improper neutralization of input during web page generation in the notification message displayed on Console and Enduser login pages when processing a malicious HTTP link. A remote attacker can generate a malicious HTTP link to execute arbitrary JavaScript in the victim's browser.
User interaction is required to open the malicious link.