{"id":"CVE-2025-57738","aliases":["GHSA-825g-mm5v-ggq4"],"url":"https://o3.security/vulnerability/CVE-2025-57738","summary":"Apache Syncope: Remote Code Execution by delegated administrators","details":"Apache Syncope offers the ability to extend / customize the base behavior on every deployment by allowing to provide custom implementations of a few Java interfaces; such implementations can be provided either as Java or Groovy classes, with the latter being particularly attractive as the machinery is set for runtime reload.\nSuch a feature has been available for a while, but recently it was discovered that a malicious administrator can inject Groovy code that can be executed remotely by a running Apache Syncope Core instance.\nUsers are recommended to upgrade to version 3.0.14 / 4.0.2, which fix this issue by forcing the Groovy code to run in a sandbox.","published":"2025-10-20T14:43:39.985Z","modified":"2026-08-12T03:51:40.024209134Z","cvss":{"score":7.2,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"},"epss":{"score":0.23107,"percentile":0.97645,"asOf":"2026-09-16"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Maven","name":"org.apache.syncope.core:syncope-core-spring","fixedVersion":"3.0.14"},{"ecosystem":"Maven","name":"org.apache.syncope.core:syncope-core-spring","fixedVersion":"4.0.2"}],"fix":null,"references":[{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2025/10/20/1"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/57xxx/CVE-2025-57738.json"},{"type":"ADVISORY","url":"https://lists.apache.org/thread/x7cv6xv7z76y49grdr1hgj1pzw5zbby6"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-57738"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:40.024209134Z"}}