CVE-2026-73195 is a vulnerability in Apache Syncope
Published on September 14, 2026
Apache Syncope: CSV export spreadsheet formula injection
Improper Encoding or Escaping of Output vulnerability in Apache Syncope.
Authenticated users can store a spreadsheet formula payload in one of their own plain attributes. When such users are included in a CSV export and the generated CSV file is opened by a spreadsheet application, the formula may be executed.
This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 Through 4.0.7, from 4.1.0-M0 through 4.1.2.
Users are recommended to upgrade to version 4.0.8 / 4.1.3, which fix this issue.
Vulnerability Analysis
CVE-2026-73195 can be exploited with network access, requires user interaction and a small amount of user privileges. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have a high impact on confidentiality and integrity, and no impact on availability.
Weakness Type
What is an Output Sanitization Vulnerability?
The software prepares a structured message for communication with another component, but encoding or escaping of the data is either missing or done incorrectly. As a result, the intended structure of the message is not preserved.
CVE-2026-73195 has been classified to as an Output Sanitization vulnerability or weakness.
Products Associated with CVE-2026-73195
Want to know whenever a new CVE is published for Apache Syncope? stack.watch will email you.
Affected Versions
Apache Software Foundation Apache Syncope:- Version 3.0.0-M0, <= 3.0.16 is affected.
- Version 4.0.0-M0, <= 4.0.7 is affected.
- Version 4.1.0-M0, <= 4.1.2 is affected.