{"schema_version": "1.6.1", "id": "CVE-2026-63071", "summary": "RCE via Groovy Sandbox bypass", "details": "Improper Isolation or Compartmentalization vulnerability in Apache Syncope.\n\nAn administrator with adequate entitlements for Implementations can create a malicious Groovy class containing untrusted code bypassing the Groovy security sandbox.\n\nThis issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 through 4.0.6, from 4.1.0-M0 through 4.1.1.\n\nUsers are recommended to upgrade to version 4.0.7 / 4.1.2, which fix this issue by tightening the Groovy security sandbox.", "affected": [{"ranges": [{"type": "SEMVER", "events": [{"introduced": "3.0.0-M0"}, {"last_affected": "3.0.0-M0"}]}, {"type": "SEMVER", "events": [{"introduced": "4.0.0-M0"}, {"last_affected": "4.0.0-M0"}]}, {"type": "SEMVER", "events": [{"introduced": "4.1.0-M0"}, {"last_affected": "4.1.0-M0"}]}]}], "references": [{"type": "WEB", "url": "https://lists.apache.org/thread/2236mlm6hbvs6g16yqz5y9s8bb7q1lo1"}]}