Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-53405

Опубликовано: 20 июл. 2026
Источник: nvd
CVSS3: 9.8
EPSS Низкий

Описание

Improper Isolation or Compartmentalization vulnerability in Apache Syncope.

An administrator with adequate entitlements can import arbitrary BPMN process definitions via the REST API and then start the process. When a BPMN process containing a Groovy scriptTask is imported and started, the Groovy script is executed directly on the server, with no sandbox.

This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 Through 4.0.6, from 4.1.0-M0 through 4.1.1.

Users are recommended to upgrade to version 4.0.7 / 4.1.2, which fix this issue by wrapping Flowable's Groovy scriptTasks with security sandbox.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:apache:syncope:*:*:*:*:*:*:*:*
Версия от 3.0.0 (включая) до 3.0.16 (включая)
cpe:2.3:a:apache:syncope:*:*:*:*:*:*:*:*
Версия от 4.0.0 (включая) до 4.0.7 (исключая)
cpe:2.3:a:apache:syncope:*:*:*:*:*:*:*:*
Версия от 4.1.0 (включая) до 4.1.2 (исключая)

EPSS

Процентиль: 37%
0.00445
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-653

Связанные уязвимости

CVSS3: 9.8
github
16 дней назад

Improper Isolation or Compartmentalization vulnerability in Apache Syncope. An administrator with adequate entitlements can import arbitrary BPMN process definitions via the REST API and then start the process. When a BPMN process containing a Groovy scriptTask is imported and started, the Groovy script is executed directly on the server, with no sandbox. This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 Through 4.0.6, from 4.1.0-M0 through 4.1.1. Users are recommended to upgrade to version 4.0.7 / 4.1.2, which fix this issue by wrapping Flowable's Groovy scriptTasks with security sandbox.

EPSS

Процентиль: 37%
0.00445
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-653