Improper isolation or compartmentalization in Apache Syncope - CVE-2026-53421

 

Improper isolation or compartmentalization in Apache Syncope - CVE-2026-53421

Published: August 24, 2026


Vulnerability identifier: #VU144734
CSH Severity: Low
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-53421
CWE-ID: CWE-653
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to execute arbitrary code.

The vulnerability exists due to improper isolation or compartmentalization in the connector subsystem when executing Groovy scripts through scripted connectors. A remote user can use REST or SQL scripted connectors to run crafted Groovy scripts to execute arbitrary code.

Exploitation requires administrative access with adequate entitlements.


Affected software

Apache Syncope

How to mitigate CVE-2026-53421

Install security update from vendor's website.

Apache Syncope - addressed in versions 4.0.7, 4.1.2

External References

Related Security Bulletins