CVE-2026-42782
Essential information
- Published
- 25/05/2026 16:16
- Modified
- 26/05/2026 19:05
- Author
- —
- Creator
- —
- CISA KEV
- No
- CWE
- —
- CVSS vector
- — — —
Description
Improper Isolation or Compartmentalization vulnerability in Apache Syncope.
An administrator with adequate entitlements for Implementations can create a malicious Groovy class containing untrusted code reaching a non-sandboxed execution path via the class static initializer.
This issue affects Apache Syncope: 3.0 through 3.0.16, 4.0 through 4.0.5, 4.1.0.
Users are recommended to upgrade to version 4.0.6 / 4.1.1, which fix this issue by forcing even the static initializer in Groovy code to run in a sandbox.
NVD status
- Status
- Undergoing Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
- Source
- [email protected]
- NVD
- View on NVD
Affected products (CPE)
| Product | CPE |
|---|---|
| apache / syncope | cpe:2.3:a:apache:syncope:3.0:*:*:*:*:*:*:* |
| apache / syncope | cpe:2.3:a:apache:syncope:<3.0.16:*:*:*:*:*:*:* |
| apache / syncope | cpe:2.3:a:apache:syncope:4.0:*:*:*:*:*:*:* |
| apache / syncope | cpe:2.3:a:apache:syncope:<4.0.5:*:*:*:*:*:*:* |
| apache / syncope | cpe:2.3:a:apache:syncope:4.1.0:*:*:*:*:*:*:* |
| apache / syncope | cpe:2.3:a:apache:syncope:4.0.6:*:*:*:*:*:*:* |
| apache / syncope | cpe:2.3:a:apache:syncope:4.1.1:*:*:*:*:*:*:* |