Apache Syncope disclosed three flaws enabling SQL injection, Groovy sandbox bypass, and privileged-user impersonation.