---
id: CVE-2025-57738
title: >-
  Apache Syncope offers the ability to extend / customize the base behavior on
  every deployment by allowing to provide custom implementations of a few Java
  interfaces; such implementations can be provided either as Java or Groovy
  classes, …
summary: >-
  Apache Syncope offers the ability to extend / customize the base behavior on
  every deployment by allowing to provide custom implementations of a few Java
  interfaces; such implementations can be provided either as Java or Groovy
  classes, …
severity: high
cvss: 7.2
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-653
vendor: apache
product: syncope
affected:
  - 'syncope >= 2.1.0, < 3.0.14'
  - 'syncope >= 4.0.0, < 4.0.2'
patched:
  - syncope 4.0.2
published: '2025-10-20'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T22:10:00.563'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-57738'
references:
  - url: 'https://lists.apache.org/thread/x7cv6xv7z76y49grdr1hgj1pzw5zbby6'
    label: security@apache.org
  - url: 'http://www.openwall.com/lists/oss-security/2025/10/20/1'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.23185
epssPercentile: 0.97719
ingestedAt: '2026-10-08T22:11:53.817Z'
---

## Overview

Apache Syncope offers the ability to extend / customize the base behavior on every deployment by allowing to provide custom implementations of a few Java interfaces; such implementations can be provided either as Java or Groovy classes, with the latter being particularly attractive as the machinery is set for runtime reload.
Such a feature has been available for a while, but recently it was discovered that a malicious administrator can inject Groovy code that can be executed remotely by a running Apache Syncope Core instance.
Users are recommended to upgrade to version 3.0.14 / 4.0.2, which fix this issue by forcing the Groovy code to run in a sandbox.

## Affected

- `syncope >= 2.1.0, < 3.0.14`
- `syncope >= 4.0.0, < 4.0.2`

## Remediation

Upgrade past the affected range:

- `syncope 4.0.2`
