
CVE-2026-42782: Apache Syncope: Post-auth RCE via Groovy static https://www.openwall.com/lists/oss-security/2026/05/25/4 CVE-2026-42797: Apache Syncope: JexlContextBuilder Information Disclosure https://www.openwall.com/lists/oss-security/2026/05/25/5
Post summary
The post announces two Apache Syncope CVEs: CVE-2026-42782 is a post‑authentication remote code execution via Groovy static use, and CVE-2026-42797 allows information disclosure through JexlContextBuilder.


