CVE-2026-42782
published 2026-05-25CVE-2026-42782: Improper Isolation or Compartmentalization vulnerability in Apache Syncope. An administrator with adequate entitlements for Implementations can create a…
PriorityP348high7.2CVSS 3.1
AVNACLPRHUINSUCHIHAH
EPSS
0.65%
47.1th percentile
Improper Isolation or Compartmentalization vulnerability in Apache Syncope.
An administrator with adequate entitlements for Implementations can create a malicious Groovy class containing untrusted code reaching a non-sandboxed execution path via the class static initializer.
This issue affects Apache Syncope: 3.0 through 3.0.16, 4.0 through 4.0.5, 4.1.0.
Users are recommended to upgrade to version 4.0.6 / 4.1.1, which fix this issue by forcing even the static initializer in Groovy code to run in a sandbox.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | syncope | — | — |
| apache | syncope | 3.0.0 – 3.0.16 | — |
| apache | syncope | >= 4.0.0 < 4.0.6 | 4.0.6 |
| apache_software_foundation | apache_syncope | 3.0 – 3.0.16 | — |
| apache_software_foundation | apache_syncope | 4.0 – 4.0.5 | — |
| apache_software_foundation | apache_syncope | 4.1 – 4.1.0 | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Apache Syncope has an Improper Isolation or Compartmentalization vulnerability
ghsa·2026-05-26
CVE-2026-42782 [HIGH] CWE-653 Apache Syncope has an Improper Isolation or Compartmentalization vulnerability
Apache Syncope has an Improper Isolation or Compartmentalization vulnerability
Improper Isolation or Compartmentalization vulnerability in Apache Syncope.
An administrator with adequate entitlements for Implementations can create a malicious Groovy class containing untrusted code reaching a non-sandboxed execution path via the class static initializer.
This issue affects Apache Syncope: 3.0 through 3.0.16, 4.0 through 4.0.5, 4.1.0.
Users are recommended to upgrade to version 4.0.6 / 4.1.1, which fix this issue by forcing even the static initializer in Groovy code to run in a sandbox.
GHSA
GHSA-gq7g-vg2q-jvq3: Improper Isolation or Compartmentalization vulnerability in Apache Syncope
ghsa_unreviewed·2026-05-26
CVE-2026-42782 [HIGH] CWE-653 GHSA-gq7g-vg2q-jvq3: Improper Isolation or Compartmentalization vulnerability in Apache Syncope
Improper Isolation or Compartmentalization vulnerability in Apache Syncope.
An administrator with adequate entitlements for Implementations can create a malicious Groovy class containing untrusted code reaching a non-sandboxed execution path via the class static initializer.
This issue affects Apache Syncope: 3.0 through 3.0.16, 4.0 through 4.0.5, 4.1.0.
Users are recommended to upgrade to version 4.0.6 / 4.1.1, which fix this issue by forcing even the static initializer in Groovy code to run in a sandbox.
VulDB
Apache Syncope up to 3.0.16/4.0.5/4.1.0 Groovy Code improper isolation or compartmentalization (EUVD-2026-31696)
vuldb·2026-05-25
CVE-2026-42782 [LOW] Apache Syncope up to 3.0.16/4.0.5/4.1.0 Groovy Code improper isolation or compartmentalization (EUVD-2026-31696)
A vulnerability was found in Apache Syncope up to 3.0.16/4.0.5/4.1.0. It has been classified as problematic. Affected by this issue is some unknown functionality of the component Groovy Code Handler. The manipulation leads to improper isolation or compartmentalization.
This vulnerability is documented as CVE-2026-42782. The attack can be initiated remotely. There is not any exploit available.
Upgrading the affected component is recommended.
CVEList
Apache Syncope: Post-auth RCE via Groovy static
cvelistv5·2026-05-25
CVE-2026-42782 CWE-653 Apache Syncope: Post-auth RCE via Groovy static
Apache Syncope: Post-auth RCE via Groovy static
Improper Isolation or Compartmentalization vulnerability in Apache Syncope.
An administrator with adequate entitlements for Implementations can create a malicious Groovy class containing untrusted code reaching a non-sandboxed execution path via the class static initializer.
This issue affects Apache Syncope: 3.0 through 3.0.16, 4.0 through 4.0.5, 4.1.0.
Users are recommended to upgrade to version 4.0.6 / 4.1.1, which fix this issue by forcing even the static initializer in Groovy code to run in a sandbox.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-05-25
Published