SEPTEMBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-53421

CRITICAL · CVSS 9.8 EPSS 0.68% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-20 · Last synced 2026-08-19

CyberRota Analysis

AI-Generated

Apache Syncope versions 3.0.0-M0 through 3.0.16, 4.0.0-M0 through 4.0.6, and 4.1.0-M0 through 4.1.1 are vulnerable to a critical remote code execution flaw due to improper isolation in the connector subsystem, allowing administrators with sufficient entitlements to execute Groovy scripts via scripted connectors. This vulnerability poses a significant risk to organizations using affected versions, particularly those with elevated administrative access. It is imperative for all users of these versions to prioritize upgrading to 4.0.7 or 4.1.2 to mitigate this security threat.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
remote code execution code execution

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-53421
Severity
CRITICAL
CVSS
9.8
EPSS
0.68%
Apache

Original NVD Description

Improper Isolation or Compartmentalization vulnerability in Apache Syncope. An administrator with adequate entitlements can achieve remote code execution through the connector subsystem by relying on scripted connectors' (REST and SQL) capability to run Groovy scripts. This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 Through 4.0.6, from 4.1.0-M0 through 4.1.1. Users are recommended to upgrade to version 4.0.7 / 4.1.2, which fix this issue by hardening the Groovy security sandbox.

Related CVEs

Other vulnerabilities affecting the same vendor(s)