VYPR

Syncope

by Apache

Source repositories

CVEs (46)

  • CVE-2026-62183CriJul 20, 2026
    risk 0.00cvss 9.8epss 0.01

    Improper Privilege Management vulnerability in Apache Syncope. When: * the all-Java user workflow adapter is configured, or * the Flowable user workflow adapter is configured, bearing a BPMN definition not requiring admin approval for user self registration of self update…

  • CVE-2026-57308CriJul 20, 2026
    risk 0.00cvss 9.8epss 0.01

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Syncope. An administrator with adequate entitlements can achieve execution of arbitrary SQL via stacked queries, leveraging unsanitized sort parameters. This issue…

  • CVE-2026-53421CriJul 20, 2026
    risk 0.00cvss 9.8epss 0.01

    Improper Isolation or Compartmentalization vulnerability in Apache Syncope. An administrator with adequate entitlements can achieve remote code execution through the connector subsystem by relying on scripted connectors' (REST and SQL) capability to run Groovy scripts. This…

  • CVE-2026-53405CriJul 20, 2026
    risk 0.00cvss 9.8epss 0.01

    Improper Isolation or Compartmentalization vulnerability in Apache Syncope. An administrator with adequate entitlements can import arbitrary BPMN process definitions via the REST API and then start the process. When a BPMN process containing a Groovy scriptTask is imported…

  • CVE-2014-3503Jul 11, 2014
    risk 0.00cvss —epss 0.06

    Apache Syncope 1.1.x before 1.1.8 uses weak random values to generate passwords, which makes it easier for remote attackers to guess the password via a brute force attack.

  • CVE-2014-0111Apr 17, 2014
    risk 0.00cvss —epss 0.03

    Apache Syncope 1.0.0 before 1.0.9 and 1.1.0 before 1.1.7 allows remote administrators to execute arbitrary Java code via vectors related to Apache Commons JEXL expressions, "derived schema definition," "user / role templates," and "account links of resource mappings."

Page 3 of 3