Impact
A privileged administrator can import arbitrary BPMN process definitions through the Apache Syncope REST API. If the imported definition contains a Groovy scriptTask, the script is executed directly on the server without any sandboxing, allowing an attacker with sufficient entitlements to run arbitrary code. This flaw, classified as improper isolation or compartmentalization (CWE-653), can compromise confidentiality, integrity and availability of the host system.
Affected Systems
This vulnerability affects all publicly released Apache Syncope versions from 3.0.0-M0 through 3.0.16, 4.0.0-M0 through 4.0.6, and 4.1.0-M0 through 4.1.1.
Risk and Exploitability
Exploiting the flaw requires administrative access to the REST API, which is an internal privilege that can be abused by a compromised or malicious administrator. The CVSS score of 9.8 signals a critical severity, while the EPSS score indicates a very low current probability of exploitation. The vulnerability is not listed in the CISA KEV catalog, yet the lack of a sandbox for execution makes it a high‑severity risk for organizations running the affected versions.
OpenCVE Enrichment