CRITICAL🇵🇱 Wersja polska

CVE-2026-53421

CVSS 9.8pub. 2026-07-20upd. 2026-07-27

Improper Isolation or Compartmentalization vulnerability in Apache Syncope. An administrator with adequate entitlements can achieve remote code execution through the connector subsystem by relying on scripted connectors' (REST and SQL) capability to run Groovy scripts. This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 Through 4.0.6, from 4.1.0-M0 through 4.1.1. Users are recommended to upgrade to version 4.0.7 / 4.1.2, which fix this issue by hardening the Groovy security sandbox.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Apache Syncope

    APP
    Apache
    3.0.0 – 3.0.164.0.0 – 4.0.7 (excl.)4.1.0 – 4.1.2 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCE
CWE
References

Related vulnerabilities

CVE-2026-62183CRITICAL9.8PL ✓same product

Apache Syncope — privilege escalation do poziomu administratora przez REST API

CVE-2026-63071CRITICAL9.8PL ✓same product

Apache Syncope – ominięcie sandboxa Groovy przez administratora

CVE-2026-57308CRITICAL9.8PL ✓same product

SQL Injection w Apache Syncope via niesanityzowane parametry sortowania

CVE-2026-53405CRITICAL9.8PL ✓same product

Apache Syncope: Wykonanie kodu Groovy bez sandbox przez BPMN REST API

CVE-2020-1961CRITICAL9.8PL ✓same product

Apache Syncope: Server-Side Template Injection w szablonach e-mail (RCE)