Improper Isolation Vulnerability in Apache Syncope by Apache
CVE-2026-63071

Currently unrated

Key Information:

Vendor

Apache

Vendor
CVE Published:
20 July 2026

What is CVE-2026-63071?

An improper isolation vulnerability has been identified in Apache Syncope, affecting specific versions ranging from 3.0.0-M0 to 4.1.1. Administrators holding adequate entitlements can inadvertently create malicious Groovy classes containing untrusted code, thereby bypassing the Groovy security sandbox. This flaw emphasizes the need for a robust security framework. Users are urged to upgrade to versions 4.0.7 or 4.1.2, which include critical enhancements to the Groovy security sandbox, mitigating this risk.

Affected Version(s)

Apache Syncope 3.0.0-M0 <= 3.0.16

Apache Syncope 4.0.0-M0 <= 4.0.6

Apache Syncope 4.1.0-M0 <= 4.1.1

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

elin kai
无聊
.