logo

Public PoC and Technical Details Disclosed for Apache Syncope RCE

ID: 9063cdfb-f13c-511e-b844-c50222191296

STIX ID: report--9063cdfb-f13c-511e-b844-c50222191296

Feed Name: securityonline.info

Threat Score
78/100

Date Published: 2026-04-20

Date Updated: 2026-04-23

Author: Ddos

...
...

SecureLayer7 disclosed CVE-2025-57738: a high-severity RCE in Apache Syncope where uploaded Groovy implementations are compiled with an unsandboxed GroovyClassLoader, allowing static initializers to execute arbitrary JVM code (including Runtime.exec and ProcessBuilder). A public PoC demonstrates root-level execution in a Docker deployment; the vendor mitigation is to upgrade to Syncope 3.0.14 or 4.0.2.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.