https://seclists.org/oss-sec/2026/q3/178: CVE-2026-53405: Apache Syncope: mote Code Execution via Flowable BPMN Groovy ScriptTask
Published Jul 20, 2026
·Updated
Affected Software
3 affected components
Apache Syncope>=3.0.0-M0<=3.0.16
Apache Syncope>=4.0.0-M0<=4.0.6
Apache Syncope>=4.1.0-M0<=4.1.1
Frequently Asked Questions
1
What is the severity of CVE-2026-53405?
The severity of CVE-2026-53405 is rated as moderate.
2
Which versions of Apache Syncope are affected by CVE-2026-53405?
Affected versions include Apache Syncope 3.0.0-M0 through 3.0.16 and 4.0.0-M0 through 4.0.6.
3
How do I fix CVE-2026-53405?
To fix CVE-2026-53405, upgrade Apache Syncope to a version that is not affected, specifically above 4.0.6.
4
What kind of vulnerability is CVE-2026-53405?
CVE-2026-53405 is a remote code execution vulnerability via Flowable BPMN Groovy ScriptTask.
5
When was CVE-2026-53405 published?
CVE-2026-53405 was published on July 20, 2026.