CVE-2026-73195: Apache Software Foundation Apache Syncope

High severity, CVSS 7.3. EPSS: 0.4% chance of exploitation in the next 30 days.

Improper Encoding or Escaping of Output vulnerability in Apache Syncope. Authenticated users can store a spreadsheet formula payload in one of their own plain attributes. When such users are included in a CSV export and the generated CSV file is opened by a spreadsheet application, the formula may be executed. This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 Through 4.0.7, from 4.1.0-M0 through 4.1.2. Users are recommended to upgrade to version 4.0.8 / 4.1.3, which fix this issue.

Affected products

  • Apache Software Foundation Apache Syncope: from 3.0.0-M0, up to and including 3.0.16; from 4.0.0-M0, up to and including 4.0.7; from 4.1.0-M0, up to and including 4.1.2

Published 2026-09-14. Last modified 2026-09-14.