Apache Syncope Improper Isolation Vulnerability Leading to Remote Code Execution via Flowable BPMN Groovy ScriptTask

Vulnerability

A vulnerability allowing remote code execution has been identified in Apache Syncope versions 3.0.0-M0 prior to 3.0.16, 4.0.0-M0 prior to 4.0.6, and 4.1.0-M0 prior to 4.1.1. This issue arises from improper isolation in the handling of BPMN process definitions. An administrator with the necessary entitlements can import arbitrary BPMN processes via the REST API. Once imported, these processes can be started, and if they include a Groovy scriptTask, the script is executed on the server without any sandboxing, posing a significant security risk.

Impact

Exploitation of this vulnerability allows for remote code execution on the server where Apache Syncope is running.

Remediation

Users are advised to upgrade to Apache Syncope versions 4.0.7 or 4.1.2, which address this vulnerability by adding a security sandbox around Flowable's Groovy scriptTasks.

Added: Jul 20, 2026, 3:40 PM
Updated: Jul 20, 2026, 3:40 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
10.0
exploitability
4.8
remediation
0.0
relevance
10.0
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.