Code Injection Vulnerability in Apache Syncope Affects Multiple Versions
CVE-2026-77147
Currently unrated
What is CVE-2026-77147?
A code injection vulnerability exists in Apache Syncope, allowing an authorized administrator to craft a malicious Groovy Command class. This malicious payload can bypass the built-in Groovy security sandbox due to improper control over the generation of code, potentially leading to unauthorized code execution. Affected versions include 3.0.0-M0 through 3.0.16, 4.0.0-M0 through 4.0.7, and 4.1.0-M0 through 4.1.2. Users are advised to upgrade to versions 4.0.8 or 4.1.3 to resolve this issue.
Affected Version(s)
Apache Syncope 3.0.0-M0 <= 3.0.16
Apache Syncope 4.0.0-M0 <= 4.0.7
Apache Syncope 4.1.0-M0 <= 4.1.2