Author: ilgrosso
Date: Mon Jul 20 09:53:28 2026
New Revision: 1936353

Log:
Updating security page

Modified:
   syncope/site/security.html

Modified: syncope/site/security.html
==============================================================================
--- syncope/site/security.html  Mon Jul 20 09:50:40 2026        (r1936352)
+++ syncope/site/security.html  Mon Jul 20 09:53:28 2026        (r1936353)
@@ -87,6 +87,368 @@
 
 <p>If you want to report a vulnerability, please follow <a 
href="https://www.apache.org/security/"; class="externalLink">the 
procedure</a>.</p>
 
+<section><a 
id="CVE-2026-63071.3A_Apache_Syncope.3A_RCE_via_Groovy_Sandbox_bypass"></a>
+<h2>CVE-2026-63071: Apache Syncope: RCE via Groovy Sandbox bypass</h2>
+
+<p>Improper Isolation or Compartmentalization vulnerability in Apache 
Syncope.</p>
+
+<p>An administrator with adequate entitlements for Implementations can create 
a malicious Groovy class containing untrusted code bypassing the Groovy 
security sandbox.</p>
+
+
+<p>
+<b>Severity</b> </p>
+
+<p>moderate</p>
+
+
+<p>
+<b>Affects</b> </p>
+
+<p>
+</p>
+<ul>
+
+<li>4.1.0-M0 through 4.1.1</li>
+
+<li>4.0.0-M0 through 4.0.6</li>
+
+<li>3.0.0-M0 through 3.0.16</li>
+</ul>
+
+
+
+<p>
+<b>Solution</b> </p>
+
+<p>
+</p>
+<ul>
+
+<li>Users are recommended to upgrade to version 4.1.2 / 4.0.7 which fix this 
issue.</li>
+</ul>
+
+
+
+<p>
+<b>Fixed in</b> </p>
+
+<p>
+</p>
+<ul>
+
+<li>Release 4.1.2</li>
+
+<li>Release 4.0.7</li>
+</ul>
+
+
+
+<p>Read the <a href="https://www.cve.org/CVERecord?id=CVE-2026-63071"; 
class="externalLink">full CVE advisory</a>.</p>
+</section>
+
+<section><a 
id="CVE-2026-62418.3A_Apache_Syncope.3A_Low-privileged_authenticated_SSRF_in_Connectors_and_Resources_check"></a>
+<h2>CVE-2026-62418: Apache Syncope: Low-privileged authenticated SSRF in 
Connectors and Resources check</h2>
+
+<p>Low-privileged authenticated Server-Side Request Forgery (SSRF) 
vulnerability in Apache Syncope via Connectors and Resources check.</p>
+
+
+<p>
+<b>Severity</b> </p>
+
+<p>moderate</p>
+
+
+<p>
+<b>Affects</b> </p>
+
+<p>
+</p>
+<ul>
+
+<li>4.1.0-M0 through 4.1.1</li>
+
+<li>4.0.0-M0 through 4.0.6</li>
+
+<li>3.0.0-M0 through 3.0.16</li>
+</ul>
+
+
+
+<p>
+<b>Solution</b> </p>
+
+<p>
+</p>
+<ul>
+
+<li>Users are recommended to upgrade to version 4.1.2 / 4.0.7 which fix this 
issue.</li>
+</ul>
+
+
+
+<p>
+<b>Fixed in</b> </p>
+
+<p>
+</p>
+<ul>
+
+<li>Release 4.1.2</li>
+
+<li>Release 4.0.7</li>
+</ul>
+
+
+
+<p>Read the <a href="https://www.cve.org/CVERecord?id=CVE-2026-62418"; 
class="externalLink">full CVE advisory</a>.</p>
+</section>
+
+<section><a 
id="CVE-2026-62183.3A_Apache_Syncope.3A_User_self-service_privilege_escalation"></a>
+<h2>CVE-2026-62183: Apache Syncope: User self-service privilege escalation</h2>
+
+<p>Improper Privilege Management vulnerability in Apache Syncope.</p>
+
+<p>When:</p>
+
+<ul>
+
+<li>the all-Java user workflow adapter is configured, or</li>
+
+<li>&gt;the Flowable user workflow adapter is configured, bearing a BPMN 
definition not requiring admin approval for user self registration of self 
update requests</li>
+</ul>
+
+<p>the following scenario could happen.<br />
+A REST API call can allow the user to grant themselves one or more of defined 
Roles, thus gaining their Entitlements and becoming in fact an administrator; 
the actual Entitlements gained depend on the Roles that are effectively defined 
on the specific Syncope deployment.</p>
+
+
+<p>
+<b>Severity</b> </p>
+
+<p>important</p>
+
+
+<p>
+<b>Affects</b> </p>
+
+<p>
+</p>
+<ul>
+
+<li>4.1.0-M0 through 4.1.1</li>
+
+<li>4.0.0-M0 through 4.0.6</li>
+
+<li>3.0.0-M0 through 3.0.16</li>
+</ul>
+
+
+
+<p>
+<b>Solution</b> </p>
+
+<p>
+</p>
+<ul>
+
+<li>Users are recommended to upgrade to version 4.1.2 / 4.0.7 which fix this 
issue.</li>
+</ul>
+
+
+
+<p>
+<b>Fixed in</b> </p>
+
+<p>
+</p>
+<ul>
+
+<li>Release 4.1.2</li>
+
+<li>Release 4.0.7</li>
+</ul>
+
+
+
+<p>Read the <a href="https://www.cve.org/CVERecord?id=CVE-2026-62183"; 
class="externalLink">full CVE advisory</a>.</p>
+</section>
+
+<section><a 
id="CVE-2026-57308.3A_Apache_Syncope.3A_SQL_injection_vulnerability_in_Audit_Events_search"></a>
+<h2>CVE-2026-57308: Apache Syncope: SQL injection vulnerability in Audit 
Events search</h2>
+
+<p>Improper Neutralization of Special Elements used in an SQL Command ('SQL 
Injection') vulnerability in Apache Syncope.</p>
+
+<p>An administrator with adequate entitlements can achieve execution of 
arbitrary SQL via stacked queries, leveraging unsanitized sort parameters.</p>
+
+
+<p>
+<b>Severity</b> </p>
+
+<p>important</p>
+
+
+<p>
+<b>Affects</b> </p>
+
+<p>
+</p>
+<ul>
+
+<li>4.1.0-M0 through 4.1.1</li>
+
+<li>4.0.0-M0 through 4.0.6</li>
+
+<li>3.0.0-M0 through 3.0.16</li>
+</ul>
+
+
+
+<p>
+<b>Solution</b> </p>
+
+<p>
+</p>
+<ul>
+
+<li>Users are recommended to upgrade to version 4.1.2 / 4.0.7 which fix this 
issue.</li>
+</ul>
+
+
+
+<p>
+<b>Fixed in</b> </p>
+
+<p>
+</p>
+<ul>
+
+<li>Release 4.1.2</li>
+
+<li>Release 4.0.7</li>
+</ul>
+
+
+
+<p>Read the <a href="https://www.cve.org/CVERecord?id=CVE-2026-57308"; 
class="externalLink">full CVE advisory</a>.</p>
+</section>
+
+<section><a 
id="CVE-2026-53421.3A_Apache_Syncope.3A_Remote_Code_Execution_via_Scripted_Connector"></a>
+<h2>CVE-2026-53421: Apache Syncope: Remote Code Execution via Scripted 
Connector</h2>
+
+<p>Improper Isolation or Compartmentalization vulnerability in Apache 
Syncope.</p>
+
+<p>An administrator with adequate entitlements can achieve remote code 
execution through the connector subsystem by relying on scripted connectors' 
(REST and SQL) capability to run Groovy scripts.</p>
+
+
+<p>
+<b>Severity</b> </p>
+
+<p>Moderate</p>
+
+
+<p>
+<b>Affects</b> </p>
+
+<p>
+</p>
+<ul>
+
+<li>4.1.0-M0 through 4.1.1</li>
+
+<li>4.0.0-M0 through 4.0.6</li>
+
+<li>3.0.0-M0 through 3.0.16</li>
+</ul>
+
+
+
+<p>
+<b>Solution</b> </p>
+
+<p>
+</p>
+<ul>
+
+<li>Users are recommended to upgrade to version 4.1.2 / 4.0.7 which fix this 
issue.</li>
+</ul>
+
+
+
+<p>
+<b>Fixed in</b> </p>
+
+<p>
+</p>
+<ul>
+
+<li>Release 4.1.2</li>
+
+<li>Release 4.0.7</li>
+</ul>
+
+
+
+<p>Read the <a href="https://www.cve.org/CVERecord?id=CVE-2026-53421"; 
class="externalLink">full CVE advisory</a>.</p>
+</section>
+
+<section><a 
id="CVE-2026-53405.3A_Apache_Syncope.3A_Remote_Code_Execution_via_Flowable_BPMN_Groovy_ScriptTask"></a>
+<h2>CVE-2026-53405: Apache Syncope: Remote Code Execution via Flowable BPMN 
Groovy ScriptTask</h2>
+
+<p>Improper Isolation or Compartmentalization vulnerability in Apache 
Syncope.</p>
+
+<p>An administrator with adequate entitlements can import arbitrary BPMN 
process definitions via the REST API and then start the process. When a BPMN 
process containing a Groovy scriptTask is imported and started, the Groovy 
script is executed directly on the server, with no sandbox.</p>
+
+
+<p>
+<b>Severity</b> </p>
+
+<p>Moderate</p>
+
+
+<p>
+<b>Affects</b> </p>
+
+<p>
+</p>
+<ul>
+
+<li>4.1.0-M0 through 4.1.1</li>
+
+<li>4.0.0-M0 through 4.0.6</li>
+
+<li>3.0.0-M0 through 3.0.16</li>
+</ul>
+
+
+
+<p>
+<b>Solution</b> </p>
+
+<p>
+</p>
+<ul>
+
+<li>Users are recommended to upgrade to version 4.1.2 / 4.0.7 which fix this 
issue.</li>
+</ul>
+
+
+
+<p>
+<b>Fixed in</b> </p>
+
+<p>
+</p>
+<ul>
+
+<li>Release 4.1.2</li>
+
+<li>Release 4.0.7</li>
+</ul>
+
+
+
+<p>Read the <a href="https://www.cve.org/CVERecord?id=CVE-2026-53405"; 
class="externalLink">full CVE advisory</a>.</p>
+</section>
+
 <section><a 
id="CVE-2026-42797.3A_Apache_Syncope.3A_JexlContextBuilder_Information_Disclosure"></a>
 <h2>CVE-2026-42797: Apache Syncope: JexlContextBuilder Information 
Disclosure</h2>
 

Reply via email to