Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.8
CVE-2026-53421: Apache Syncope Remote Code Execution via Scripted Connectors
CVE-2026-53421 · published 2 months ago
Summary
Apache Syncope, a user identity management system, has a security flaw that allows an authorized administrator to execute malicious code remotely. This could lead to unauthorized access or data breaches. To fix this issue, users should update to the latest version of Apache Syncope, specifically 4.0.7 or 4.1.2, which includes security patches.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| apache software foundation | apache syncope | <= 3.0.16 |
Original advisory text
Improper Isolation or Compartmentalization vulnerability in Apache Syncope.
An administrator with adequate entitlements can achieve remote code execution through the connector subsystem by relyi...
Improper Isolation or Compartmentalization vulnerability in Apache Syncope.
An administrator with adequate entitlements can achieve remote code execution through the connector subsystem by relying on scripted connectors' (REST and SQL) capability to run Groovy scripts.
This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 Through 4.0.6, from 4.1.0-M0 through 4.1.1.
Users are recommended to upgrade to version 4.0.7 / 4.1.2, which fix this issue by hardening the Groovy security sandbox.
An administrator with adequate entitlements can achieve remote code execution through the connector subsystem by relying on scripted connectors' (REST and SQL) capability to run Groovy scripts.
This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 Through 4.0.6, from 4.1.0-M0 through 4.1.1.
Users are recommended to upgrade to version 4.0.7 / 4.1.2, which fix this issue by hardening the Groovy security sandbox.
Severity
9.8
Critical
Exploitation
EPSS 1%
Type
CWE-653Improper Isolation or Compartmentalization
Timeline
Published20 Jul 2026
Updated25 Sep 2026
First seen20 Jul 2026
Track software like this
Free during beta