Code Injection Vulnerability in Apache Syncope Affects Multiple Versions
CVE-2026-77147

Currently unrated

Key Information:

Vendor

Apache

Vendor
CVE Published:
14 September 2026

What is CVE-2026-77147?

A code injection vulnerability exists in Apache Syncope, allowing an authorized administrator to craft a malicious Groovy Command class. This malicious payload can bypass the built-in Groovy security sandbox due to improper control over the generation of code, potentially leading to unauthorized code execution. Affected versions include 3.0.0-M0 through 3.0.16, 4.0.0-M0 through 4.0.7, and 4.1.0-M0 through 4.1.2. Users are advised to upgrade to versions 4.0.8 or 4.1.3 to resolve this issue.

Affected Version(s)

Apache Syncope 3.0.0-M0 <= 3.0.16

Apache Syncope 4.0.0-M0 <= 4.0.7

Apache Syncope 4.1.0-M0 <= 4.1.2

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

n0mi1k
.