VYPR
Unrated severityNVD Advisory· Published May 25, 2026· Updated May 25, 2026

Apache Syncope: Post-auth RCE via Groovy static

CVE-2026-42782

Description

Improper Isolation or Compartmentalization vulnerability in Apache Syncope.

An administrator with adequate entitlements for Implementations can create a malicious Groovy class containing untrusted code reaching a non-sandboxed execution path via the class static initializer.

This issue affects Apache Syncope: 3.0 through 3.0.16, 4.0 through 4.0.5, 4.1.0.

Users are recommended to upgrade to version 4.0.6 / 4.1.1, which fix this issue by forcing even the static initializer in Groovy code to run in a sandbox.

Affected products

2
  • Apache/Syncopeinferred2 versions
    >=3.0,<=3.0.16,>=4.0,<=4.0.5,=4.1.0+ 1 more
    • (no CPE)range: >=3.0,<=3.0.16,>=4.0,<=4.0.5,=4.1.0
    • (no CPE)range: 3.0 through 3.0.16, 4.0 through 4.0.5, 4.1.0

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.