VYPR
High severity7.2NVD Advisory· Published May 25, 2026· Updated Jul 24, 2026

CVE-2026-42782

CVE-2026-42782

Description

Improper Isolation or Compartmentalization vulnerability in Apache Syncope.

An administrator with adequate entitlements for Implementations can create a malicious Groovy class containing untrusted code reaching a non-sandboxed execution path via the class static initializer.

This issue affects Apache Syncope: 3.0 through 3.0.16, 4.0 through 4.0.5, 4.1.0.

Users are recommended to upgrade to version 4.0.6 / 4.1.1, which fix this issue by forcing even the static initializer in Groovy code to run in a sandbox.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
org.apache.syncope.core:syncope-core-springMaven
>= 3.0.0-M0, <= 3.0.16
org.apache.syncope.core:syncope-core-springMaven
>= 4.0.0-M0, < 4.0.64.0.6
org.apache.syncope.core:syncope-core-springMaven
>= 4.1.0-M0, < 4.1.14.1.1

Affected products

4
  • Apache/Syncopeinferred4 versions
    >=3.0,<=3.0.16,>=4.0,<=4.0.5,=4.1.0+ 3 more
    • (no CPE)range: >=3.0,<=3.0.16,>=4.0,<=4.0.5,=4.1.0
    • cpe:2.3:a:apache:syncope:*:*:*:*:*:*:*:*range: >=3.0.0,<=3.0.16
    • cpe:2.3:a:apache:syncope:4.1.0:*:*:*:*:*:*:*
    • (no CPE)range: 3.0 - 3.0.16, 4.0 - 4.0.5, 4.1.0

Patches

Vulnerability mechanics

References

4

News mentions

2