Apache Syncope Console XML External Entity Vulnerability in Keymaster Parameters

Vulnerability

A vulnerability allowing improper restriction of XML external entity references has been identified in the Apache Syncope Console, specifically in versions 3.0.0 to 3.0.15 and 4.0.0 to 4.0.3. This vulnerability allows an administrator with the right permissions to create or edit Keymaster parameters to craft malicious XML that can be used to launch an XML external entity (XXE) attack, leading to unauthorized access to sensitive data.

Impact

Exploitation of this vulnerability could result in an XXE attack, allowing for the manipulation of XML data processing and potentially leading to the disclosure of sensitive information.

Remediation

Users are advised to upgrade to Apache Syncope versions 3.0.16 or 4.0.4, which address this vulnerability.

Added: Feb 3, 2026, 4:18 PM
Updated: Feb 3, 2026, 4:48 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
4.8
remediation
0.0
relevance
2.5
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.