CVE-2026-53421Apache · Syncope
Vulnerability data via NVD (ingested)
Improper Isolation or Compartmentalization vulnerability in Apache Syncope. An administrator with adequate entitlements can achieve remote code execution through the connector subsystem by relying on scripted connectors' (REST and SQL) capability to run Groovy scripts. This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 Through 4.0.6, from 4.1.0-M0 through 4.1.1. Users are recommended to upgrade to version 4.0.7 / 4.1.2, which fix this issue by hardening the Groovy security sandbox.
External references
Search for exposed instances
Shodan + Censys queries derived from NVD's CPE data. The vuln tag catches assets Shodan has explicitly linked to this CVE; the product / banner fingerprints find exposed instances even when the vuln tag was never applied (which is common).
vuln:CVE-2026-53421product:"Apache Syncope"http.html:"Syncope"More intel sources (5)
vuln:CVE-2026-53421vulnerabilities.cve_id: CVE-2026-53421CVE-2026-53421CVE-2026-53421"CVE-2026-53421" exploit -site:nvd.nist.gov