Stats Digest Feeds
← Back to all CVEs

CVE-2026-77147

MEDIUM NVD
CVSS Score 6.5
Severity MEDIUM
Published Sep 14, 2026
Vendor unknown

Description

Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Syncope. An administrator with adequate entitlements for Implementations can create a malicious Groovy Command class containing untrusted code in their CommandArgs static implementation,Β bypassing the Groovy security sandbox. This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 Through 4.0.7, from 4.1.0-M0 through 4.1.2. Users are recommended to upgrade to version 4.0.8 / 4.1.3, which fix this issue.

References