CVE-2026-77147

LOWCVSS 6.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Syncope. An administrator with adequate entitlements for Implementations can create a malicious Groovy Command class containing untrusted code in their CommandArgs static implementation, bypassing the Groovy security sandbox. This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 Through 4.0.7, from 4.1.0-M0 through 4.1.2. Users are recommended to upgrade to version 4.0.8 / 4.1.3, which fix this issue.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-94

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-09-24: 109-24
Referenced assets1 URL
Full discourse1 post
  • iototsecnews@iototsecnews

    Apache Syncope の脆弱性である CVE-2026-82232/77147/73178 が FIX:深刻な SQLi などの恐れ https://iototsecnews.jp/2026/09/16/apache-syncope-vulnerabilities-allow-attackers-to-execute-malicious-code-and-bypass-controls/ ID 管理基盤の Apache Syncope において、重大な問題が確認されました。この記事は、脆弱性 CVE-2026-82232/CVE-2026-77147/CVE-2026-73178 の詳細な情報を伝えています。入力値の不十分な検証や安全でない処理構造が原因です。悪用された場合の影響として、機密情報の漏洩/データの破棄/任意コードの実行/高権限アカウントへのなりすましなどの被害が懸念されます。安全に運用するための対応策として、修正済みバージョンへの更新/特権アカウントの精査/アクセストークンの更新/ログ監視の徹底といった措置が求められます。システムを守るためにも、迅速な状況確認をおすすめします。 #Apache #CVE202673178 #CVE202677147 #CVE202682232 #Syncope #Vulnerability

    0001076
    514 followersView on X

Explore more