logo

Apache Syncope RCE Vulnerability Detailed After Public Exploit Code Release

ID: b3e170dd-7246-5aa2-8f1b-cfddbad7f978

STIX ID: report--b3e170dd-7246-5aa2-8f1b-cfddbad7f978

Feed Name: GBHackers

Threat Score
75/100

Date Published: 2026-04-21

Date Updated: 2026-04-22

Author: Divya

...
...

Security researchers disclosed CVE-2025-57738, a high-severity (CVSS 7.2) remote code execution vulnerability in Apache Syncope's Groovy-based ImplementationManager that allows authenticated administrators to upload malicious Groovy classes which execute at compile time and can invoke full JVM APIs—leading to full system compromise in containerized/root deployments; a public PoC was published and Syncope 3.0.14 / 4.0.2 contain fixes that implement a Groovy sandbox and API blacklists, so affected deployments should upgrade and audit privileged accounts immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.