CVE-2023-34923: Topdesk

High severity, CVSS 8.1. EPSS: 0.7% chance of exploitation in the next 30 days.

XML Signature Wrapping (XSW) in SAML-based Single Sign-on feature in TOPdesk v12.10.12 allows bad actors with credentials to authenticate with the Identity Provider (IP) to impersonate any TOPdesk user via SAML Response manipulation.

Affected products

  • Topdesk Topdesk: version 12.10.12 only

Published 2023-06-22. Last modified 2026-06-17.