SEPTEMBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-63071

CRITICAL · CVSS 9.8 EPSS 0.44%

Source: NVD + CISA KEV + EPSS · Published 2026-07-20 · Last synced 2026-08-19

CyberRota Analysis

AI-Generated

A critical vulnerability in Apache Syncope allows an administrator with sufficient permissions to create a malicious Groovy class that can bypass the Groovy security sandbox, potentially leading to the execution of untrusted code. This affects versions 3.0.0-M0 through 3.0.16, 4.0.0-M0 through 4.0.6, and 4.1.0-M0 through 4.1.1. Organizations using affected versions should prioritize upgrading to 4.0.7 or 4.1.2 to mitigate this risk.

CVE
CVE-2026-63071
Severity
CRITICAL
CVSS
9.8
EPSS
0.44%
Apache

Original NVD Description

Improper Isolation or Compartmentalization vulnerability in Apache Syncope. An administrator with adequate entitlements for Implementations can create a malicious Groovy class containing untrusted code bypassing the Groovy security sandbox. This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 through 4.0.6, from 4.1.0-M0 through 4.1.1. Users are recommended to upgrade to version 4.0.7 / 4.1.2, which fix this issue by tightening the Groovy security sandbox.

Related CVEs

Other vulnerabilities affecting the same vendor(s)