CVE-2026-53421

Improper Isolation or Compartmentalization vulnerability in Apache Syncope. An administrator with adequate entitlements can achieve remote code execution through the connector subsystem by relying on scripted connectors' (REST and SQL) capability to run Groovy scripts. This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 Through 4.0.6, from 4.1.0-M0 through 4.1.1. Users are recommended to upgrade to version 4.0.7 / 4.1.2, which fix this issue by hardening the Groovy security sandbox.
Configurations

No configuration.

History

21 Jul 2026, 16:17

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8

20 Jul 2026, 19:17

Type Values Removed Values Added
References
  • () http://www.openwall.com/lists/oss-security/2026/07/20/7 -

20 Jul 2026, 15:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-20 15:16

Updated : 2026-07-21 16:17


NVD link : CVE-2026-53421

Mitre link : CVE-2026-53421

CVE.ORG link : CVE-2026-53421


JSON object : View

Products Affected

No product.

CWE
CWE-653

Improper Isolation or Compartmentalization