Vulnerability Description
Improper Isolation or Compartmentalization vulnerability in Apache Syncope. An administrator with adequate entitlements can achieve remote code execution through the connector subsystem by relying on scripted connectors' (REST and SQL) capability to run Groovy scripts. This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 Through 4.0.6, from 4.1.0-M0 through 4.1.1. Users are recommended to upgrade to version 4.0.7 / 4.1.2, which fix this issue by hardening the Groovy security sandbox.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Apache | Syncope | >= 3.0.0, <= 3.0.16 |
Related Weaknesses (CWE)
References
- https://lists.apache.org/thread/nmzvz6gb2ldm30wvyk613r8dfrb6r8yxMailing ListVendor Advisory
- http://www.openwall.com/lists/oss-security/2026/07/20/7Mailing ListThird Party Advisory
FAQ
What is CVE-2026-53421?
CVE-2026-53421 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Improper Isolation or Compartmentalization vulnerability in Apache Syncope. An administrator with adequate entitlements can achieve remote code execution through the connector subsystem by relying ...
How severe is CVE-2026-53421?
CVE-2026-53421 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2026-53421?
Check the references section above for vendor advisories and patch information. Affected products include: Apache Syncope.