Improper Isolation Vulnerability in Apache Syncope by Apache
CVE-2026-63071
Currently unrated
What is CVE-2026-63071?
An improper isolation vulnerability has been identified in Apache Syncope, affecting specific versions ranging from 3.0.0-M0 to 4.1.1. Administrators holding adequate entitlements can inadvertently create malicious Groovy classes containing untrusted code, thereby bypassing the Groovy security sandbox. This flaw emphasizes the need for a robust security framework. Users are urged to upgrade to versions 4.0.7 or 4.1.2, which include critical enhancements to the Groovy security sandbox, mitigating this risk.
Affected Version(s)
Apache Syncope 3.0.0-M0 <= 3.0.16
Apache Syncope 4.0.0-M0 <= 4.0.6
Apache Syncope 4.1.0-M0 <= 4.1.1