CVE-2026-73195
Improper Encoding or Escaping of Output vulnerability in Apache Syncope. Authenticated users can store a spreadsheet formula payload in one of their own plain attributes. When such users are included in a CSV export and the generated CSV file is opened by a spreadsheet application, the formula may be executed. This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 Through 4.0.7, from 4.1.0-M0 through 4.1.2. Users are recommended to upgrade to version 4.0.8 / 4.1.3, which fix this issue.
Scoring
- Severity
- HIGH
- CVSS base score
- 7.3
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N
- EPSS probability
- 0.34%
- CWE
- CWE-116
- Published
- 2026-09-14
- Last modified
- 2026-09-14
Affected products
- Apache Software Foundation Apache Syncope
- Apache Software Foundation Apache Syncope
- Apache Software Foundation Apache Syncope
Weakness type
Related vulnerabilities
- CVE-2026-20245 — Cisco Catalyst SD-WAN Controller Authenticated Privilege Escalation Vulnerability
- CVE-2025-55730 — XWiki Remote Macros vulnerable to remote code execution using the confluence paste code macro
- CVE-2025-55729 — XWiki Remote Macros vulnerable to remote code execution using the ConfluenceLayoutSection macro
- CVE-2026-22792 — 5ire vulnerable to Remote Code Execution (RCE)
- CVE-2025-59936 — get-jwks poisoned JWKS cache allows post-fetch issuer validation bypass
- CVE-2025-59158 — Coolify has Stored XSS in Project Name
- CVE-2026-32754 — FreeScout: Stored XSS via Unescaped Email Template Rendering ({!! $thread->body !!})
- CVE-2025-40547 — SolarWinds Serv-U Logic Abuse - Remote Code Execution Vulnerability