SB20260824133 - Multiple vulnerabilities in Apache Syncope
Published: August 24, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 6 vulnerabilities.
1) Improper isolation or compartmentalization (CVE-ID: CVE-2026-53405)
CWE-ID: CWE-653 - Improper isolation or compartmentalization
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to execute arbitrary code.
The vulnerability exists due to improper isolation or compartmentalization in Flowable BPMN Groovy scriptTask handling when importing and starting a crafted BPMN process definition via the REST API. A remote user can import a BPMN process definition containing a Groovy scriptTask and start the process to execute arbitrary code.
Exploitation requires administrative entitlements to import process definitions and start the process.
2) Improper isolation or compartmentalization (CVE-ID: CVE-2026-53421)
CWE-ID: CWE-653 - Improper isolation or compartmentalization
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to execute arbitrary code.
The vulnerability exists due to improper isolation or compartmentalization in the connector subsystem when executing Groovy scripts through scripted connectors. A remote user can use REST or SQL scripted connectors to run crafted Groovy scripts to execute arbitrary code.
Exploitation requires administrative access with adequate entitlements.
3) SQL injection (CVE-ID: CVE-2026-57308)
CWE-ID: CWE-89 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVSSv4: 7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:H/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to execute arbitrary SQL.
The vulnerability exists due to SQL injection in Audit Events search when processing unsanitized sort parameters. A remote privileged user can supply crafted sort parameters with stacked queries to execute arbitrary SQL.
4) Improper privilege management (CVE-ID: CVE-2026-62183)
CWE-ID: CWE-269 - Improper Privilege Management
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to escalate privileges.
The vulnerability exists due to improper privilege management in the user self-service REST API when processing self-registration or self-update requests under affected workflow adapter configurations. A remote user can send a crafted REST API call to escalate privileges.
Exploitation is possible when the all-Java user workflow adapter is configured, or when the Flowable user workflow adapter is used with a BPMN definition that does not require admin approval for user self-registration or self-update requests.
5) Server-Side Request Forgery (SSRF) (CVE-ID: CVE-2026-62418)
CWE-ID: CWE-918 - Server-Side Request Forgery (SSRF)
CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to perform server-side request forgery.
The vulnerability exists due to improper control of outgoing network requests in connectors and resources check when handling check operations. A remote user can trigger a crafted check to perform server-side request forgery.
6) Improper isolation or compartmentalization (CVE-ID: CVE-2026-63071)
CWE-ID: CWE-653 - Improper isolation or compartmentalization
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to execute arbitrary code.
The vulnerability exists due to improper isolation or compartmentalization in the Groovy security sandbox when processing administrator-supplied Groovy implementations. A remote user can create a malicious Groovy class containing untrusted code to execute arbitrary code.
Exploitation requires administrative entitlements for Implementations.
Remediation
Install update from vendor's website.
References
- https://lists.apache.org/api/email.lua?id=85xt6oh93wj3j4n3ypq4c0bbf1zovs26
- https://syncope.apache.org/
- https://lists.apache.org/api/email.lua?id=nmzvz6gb2ldm30wvyk613r8dfrb6r8yx
- https://lists.apache.org/api/email.lua?id=g0gpctj90pbczbjl5jr33t8gr1gltg8v
- https://lists.apache.org/api/email.lua?id=6r8cngvy43y2yk4jj3w060dt8vx0yzpr
- https://lists.apache.org/api/email.lua?id=n632drbsmfr6t3p6jt6jwbjvokqdyszb
- https://lists.apache.org/api/email.lua?id=2236mlm6hbvs6g16yqz5y9s8bb7q1lo1