Apache Syncope Groovy Sandbox Bypass Vulnerability Allowing Remote Code Execution

Vulnerability

A vulnerability allowing remote code execution has been identified in Apache Syncope versions 3.0.0-M0 prior to 3.0.16, 4.0.0-M0 prior to 4.0.6, and 4.1.0-M0 prior to 4.1.1. This issue arises from improper isolation in the Groovy security sandbox, which can be bypassed by an administrator with the right entitlements. Such an administrator can create a malicious Groovy class containing untrusted code that exploits this weakness.

Impact

Exploitation of this vulnerability allows for remote code execution on the server where Apache Syncope is running.

Remediation

Users are advised to upgrade to Apache Syncope versions 4.0.7 or 4.1.2, both of which address this vulnerability by reinforcing the Groovy security sandbox.

Added: Jul 20, 2026, 5:22 PM
Updated: Jul 20, 2026, 5:22 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
5.0
exploitability
4.2
remediation
0.0
relevance
10.0
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.