CVE-2026-53421

Improper Isolation or Compartmentalization vulnerability in Apache Syncope. An administrator with adequate entitlements can achieve remote code execution through the connector subsystem by relying on scripted connectors' (REST and SQL) capability to run Groovy scripts. This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 Through 4.0.6, from 4.1.0-M0 through 4.1.1. Users are recommended to upgrade to version 4.0.7 / 4.1.2, which fix this issue by hardening the Groovy security sandbox.
References
Link Resource
https://lists.apache.org/thread/nmzvz6gb2ldm30wvyk613r8dfrb6r8yx Mailing List Vendor Advisory
http://www.openwall.com/lists/oss-security/2026/07/20/7 Mailing List Third Party Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:apache:syncope:*:*:*:*:*:*:*:*
cpe:2.3:a:apache:syncope:*:*:*:*:*:*:*:*
cpe:2.3:a:apache:syncope:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-07-20 15:16

Updated : 2026-07-27 15:00


NVD link : CVE-2026-53421

Mitre link : CVE-2026-53421

CVE.ORG link : CVE-2026-53421


JSON object : View

Products Affected

apache

  • syncope
CWE
CWE-653

Improper Isolation or Compartmentalization