Apache Syncope Vulnerabilities Allow Attackers to Execute Malicious Code and Bypass Controls
2026/09/16 CyberSecurityNews — Apache Syncope が公表したのは、権限を持つ管理者による悪意の SQL コマンドの実行/Groovy サンドボックス保護の回避/高権限ユーザーへのなりすましなどにつながる、3 件の深刻なセキュリティ脆弱性の情報である。これらの問題は、Apache Syncope 3.0/4.0/4.1 の複数のリリースに影響するものであり、すでにバージョン 4.0.8/4.1.3 で修正済みである。