logo

Apache Syncope RCE Vulnerability – Public PoC and Technical Details Released

ID: e34d2c38-b156-5df4-b9ec-3e9c4bc0ce9c

STIX ID: report--e34d2c38-b156-5df4-b9ec-3e9c4bc0ce9c

Feed Name: Cyber Press

Threat Score
75/100

Date Published: 2026-04-21

Date Updated: 2026-04-21

Author: AnuPriya

...
...

Security researchers disclosed CVE-2025-57738, a CVSS 7.2 remote code execution flaw in Apache Syncope caused by unsandboxed Groovy class loading that allows authenticated administrative users to upload malicious Groovy classes which execute during compilation; a public PoC demonstrating root-level execution (including evidence like “uid=0(root)”) was published, and Apache released fixes in Syncope 3.0.14 and 4.0.2 — organisations should upgrade immediately and audit admin/delegated accounts.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.