Junglewise Threat Intelligence

CVE-2026-73195: Apache Syncope formula injection in CSV export

CVE-2026-73195 · Severity: high · CVSS 7.3 · Published 2026-09-14

Vendors: Apache.

Executive brief

Apache Syncope is an identity and access management platform used to manage user accounts and credentials. An authenticated attacker can inject malicious spreadsheet formulas into user attributes, which are then executed when the resulting CSV file is opened in a spreadsheet application. This could lead to unauthorized data access, system compromise, or credential theft.

Technical details

This is an Improper Encoding or Escaping of Output vulnerability (CWE-117/CWE-1025) affecting Apache Syncope's CSV export functionality. An authenticated attacker can store a malicious spreadsheet formula payload (e.g., =cmd|'/c calc'!A1) in plain user attributes. When administrators export users to CSV and open the file in applications like Excel or LibreOffice, the formula is automatically executed, potentially allowing command execution or data exfiltration. The vulnerability requires prior authentication to Syncope and user action (opening the CSV file) to trigger exploitation. Patches are available in versions 4.0.8, 4.1.3, and later.

Affected products

  • Apache Syncope 3.0.0-M0 through 3.0.16, 4.0.0-M0 through 4.0.7, 4.1.0-M0 through 4.1.2

Timeline

  • 2026-09-14: disclosed

References