
CVE-2026-42782: Apache Syncope: Post-auth RCE via Groovy static https://www.openwall.com/lists/oss-security/2026/05/25/4 CVE-2026-42797: Apache Syncope: JexlContextBuilder Information Disclosure https://www.openwall.com/lists/oss-security/2026/05/25/5
Post summary
The snippet announces two new Apache Syncope vulnerabilities: CVE-2026-42782, a post-auth RCE via Groovy static, and CVE-2026-42797, an information disclosure in JexlContextBuilder, with links to Openwall discussion threads.

