CVE-2025-57738: Apache Syncope

High severity, CVSS 7.2. EPSS: 23.2% chance of exploitation in the next 30 days.

Apache Syncope offers the ability to extend / customize the base behavior on every deployment by allowing to provide custom implementations of a few Java interfaces; such implementations can be provided either as Java or Groovy classes, with the latter being particularly attractive as the machinery is set for runtime reload. Such a feature has been available for a while, but recently it was discovered that a malicious administrator can inject Groovy code that can be executed remotely by a running Apache Syncope Core instance. Users are recommended to upgrade to version 3.0.14 / 4.0.2, which fix this issue by forcing the Groovy code to run in a sandbox.

Affected products

  • Apache Syncope: from 2.1.0, before 3.0.14 (fixed in 3.0.14); from 4.0.0, before 4.0.2 (fixed in 4.0.2)

Published 2025-10-20. Last modified 2026-10-08.