Syncope CVE Vulnerabilities
By Apache — 2 known vulnerabilities
Critical
0
High
1
Medium
1
Low
0
None
0
All Syncope CVEs
CVE-2026-42797
4.9
medium
Exposure of Sensitive Information Through Data Queries vulnerability in Apache Syncope. An administrator with adequate entitlements for Derived Schemas can create a malicious JEXL expression which allows any administrator with sufficient entitlements for User read to access User-related security-se
May 25, 2026
CVE-2026-42782
7.2
high
Improper Isolation or Compartmentalization vulnerability in Apache Syncope. An administrator with adequate entitlements for Implementations can create a malicious Groovy class containing untrusted code reaching a non-sandboxed execution path via the class static initializer. This issue affects Apa
May 25, 2026