HIGHVulnerability
Verified
Global

NVD HIGH: CVE-2026-42782 — Improper Isolation or Compartmentalization vulnerability in Apache Syncope. An ...

·Source: NIST NVD

Updated:

Executive Summary

Improper Isolation or Compartmentalization vulnerability in Apache Syncope. An administrator with adequate entitlements for Implementations can create a malicious Groovy class containing untrusted code reaching a non-sandboxed execution path via the class static initializer. This issue affects Apache Syncope: 3.0 through 3.0.16, 4.0 through 4.0.5, 4.1.0. Users are recommended to upgrade to ve

Analysis

Improper Isolation or Compartmentalization vulnerability in Apache Syncope. An administrator with adequate entitlements for Implementations can create a malicious Groovy class containing untrusted code reaching a non-sandboxed execution path via the class static initializer. This issue affects Apache Syncope: 3.0 through 3.0.16, 4.0 through 4.0.5, 4.1.0. Users are recommended to upgrade to version 4.0.6 / 4.1.1, which fix this issue by forcing even the static initializer in Groovy code to run in a sandbox. CVSS Score: 7.2. Published: 2026-05-25T16:16:19.717.

Indicators of Compromise (1)

CVE (1)
CVE-2026-42782
Source Attribution

Originally published by NIST NVD on May 25, 2026. Verified by: NIST.

Related Threats