Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

Improper Isolation or Compartmentalization vulnerability in Apache Syncope. (CVE-2026-53421)CVE-2026-53421
0

Apache Syncope contains an improper isolation vulnerability that allows an administrator with sufficient entitlements to achieve remote code execution via the connector subsystem. This occurs because scripted connectors (REST and SQL) can run Groovy scripts without adequate sandboxing. The issue affects multiple versions of Apache Syncope prior to 4.0.7 and 4.1.2, which include fixes that harden the Groovy security sandbox.

Join the discussion
Improper Isolation or Compartmentalization vulnerability in Apache Syncope. (CVE-2026-63071)CVE-2026-63071
0

Apache Syncope contains an improper isolation or compartmentalization vulnerability (CVE-2026-63071) that allows an administrator with sufficient entitlements to create a malicious Groovy class containing untrusted code, bypassing the Groovy security sandbox. This affects versions from 3.0.0-M0 through 3.0.16, 4.0.0-M0 through 4.0.6, and 4.1.0-M0 through 4.1.1. The issue is fixed in versions 4.0.7 and 4.1.2 by tightening the Groovy security sandbox.

Join the discussion
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Syncope. (CVE-2026-57308)CVE-2026-57308
0

Apache Syncope contains an SQL Injection vulnerability (CVE-2026-57308) that allows an administrator with sufficient privileges to execute arbitrary SQL commands via unsanitized sort parameters. This affects versions from 3.0.0-M0 through 3.0.16, 4.0.0-M0 through 4.0.6, and 4.1.0-M0 through 4.1.1. The issue is fixed in versions 4.0.7 and 4.1.2.

Join the discussion
Improper Isolation or Compartmentalization vulnerability in Apache Syncope. (CVE-2026-53405)CVE-2026-53405
0

Apache Syncope contains an improper isolation vulnerability allowing an administrator with sufficient entitlements to import and start BPMN process definitions via the REST API. Specifically, when a BPMN process includes a Groovy scriptTask, the Groovy script executes directly on the server without sandboxing. This affects versions from 3.0.0-M0 through 3.0.16, 4.0.0-M0 through 4.0.6, and 4.1.0-M0 through 4.1.1. Upgrading to versions 4.0.7 or 4.1.2 mitigates the issue by adding a security sandbox around Groovy scriptTasks.

Join the discussion
Improper Privilege Management vulnerability in Apache Syncope. (CVE-2026-62183)CVE-2026-62183
0

An Improper Privilege Management vulnerability exists in Apache Syncope versions 3.0.0-M0 through 3.0.16, 4.0.0-M0 through 4.0.6, and 4.1.0-M0 through 4.1.1. When configured with either the all-Java or Flowable user workflow adapter using a BPMN definition that does not require admin approval for user self-registration or self-update requests, a REST API call can allow users to grant themselves one or more roles. This effectively grants them the entitlements of those roles, potentially elevating their privileges to administrator level depending on the deployment's role definitions. Users are advised to upgrade to versions 4.0.7 or 4.1.2, which address this issue.

Join the discussion
CVE-2026-57308: CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in Apache Software Foundation Apache SyncopeCVE-2026-57308
0

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Syncope. An administrator with adequate entitlements can achieve execution of arbitrary SQL via stacked queries, leveraging unsanitized sort parameters. This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 Through 4.0.6, from 4.1.0-M0 through 4.1.1. Users are recommended to upgrade to version 4.0.7 / 4.1.2, which fix this issue.

Join the discussion
CVE-2026-53421: CWE-653 Improper Isolation or Compartmentalization in Apache Software Foundation Apache SyncopeCVE-2026-53421
0

Improper Isolation or Compartmentalization vulnerability in Apache Syncope. An administrator with adequate entitlements can achieve remote code execution through the connector subsystem by relying on scripted connectors' (REST and SQL) capability to run Groovy scripts. This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 Through 4.0.6, from 4.1.0-M0 through 4.1.1. Users are recommended to upgrade to version 4.0.7 / 4.1.2, which fix this issue by hardening the Groovy security sandbox.

Join the discussion

Showing 1 to 7 of 7 results

Filters:Package: pkg:maven/org.apache.syncope/syncope-core
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses