Apache Syncope Flaws Let Users Gain Admin Roles and Execute Remote Code
ID: b63f4f15-bf6f-5aac-875e-476326f4b5ef
STIX ID: report--b63f4f15-bf6f-5aac-875e-476326f4b5ef
Feed Name: GBHackers
**Executive Summary:** Apache Syncope released patched versions 4.1.24.1, 4.1.24.1.2, and 4.0.74.0.7 to fix multiple vulnerabilities—most notably a self-service privilege escalation (CVE-2026-62183), Groovy-related remote code execution issues, an SQL injection in Audit Events (CVE-2026-57308), and an authenticated SSRF (CVE-2026-62418)—affecting the 3.0, 4.0, and 4.1 branches; administrators are advised to upgrade, review role/workflow definitions, inspect Groovy and BPMN implementations, and audit REST and connector activity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
