Vulnerability Description
Improper Isolation or Compartmentalization vulnerability in Apache Syncope. An administrator with adequate entitlements can import arbitrary BPMN process definitions via the REST API and then start the process. When a BPMN process containing a Groovy scriptTask is imported and started, the Groovy script is executed directly on the server, with no sandbox. This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 Through 4.0.6, from 4.1.0-M0 through 4.1.1. Users are recommended to upgrade to version 4.0.7 / 4.1.2, which fix this issue by wrapping Flowable's Groovy scriptTasks with security sandbox.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Apache | Syncope | >= 3.0.0, <= 3.0.16 |
Related Weaknesses (CWE)
References
- https://lists.apache.org/thread/vdq0tk6ylffz6trbgbllj9kb1ndzff7kMailing ListVendor Advisory
- http://www.openwall.com/lists/oss-security/2026/07/20/6Mailing ListThird Party Advisory
FAQ
What is CVE-2026-53405?
CVE-2026-53405 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Improper Isolation or Compartmentalization vulnerability in Apache Syncope. An administrator with adequate entitlements can import arbitrary BPMN process definitions via the REST API and then start t...
How severe is CVE-2026-53405?
CVE-2026-53405 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2026-53405?
Check the references section above for vendor advisories and patch information. Affected products include: Apache Syncope.