{"api_version":"v1","generated_at":"2026-10-05T10:30:00+00:00","product":{"cve_count":40,"evidence_gap_note":"This identity is present in BlackTree CVE records, but no product-specific publisher support or retirement history is currently registered in Lifecycle.","id":"security:cve-apache-software-foundation-apache-syncope-6beafb6e4908","lifecycle_state":"evidence_gap","linked_lifecycle_url":null,"name":"Apache Syncope","next_cursor":null,"observations":[{"affected":"Apache Syncope: 3.0.0-M0 \u2264 3.0.16, 4.0.0-M0 \u2264 4.0.7, 4.1.0-M0 \u2264 4.1.2","affected_versions_present":true,"cve_id":"CVE-2026-73191","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-73191","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-09-14T19:32:54.329Z","patch_url":"","primary_source":"","published":"2026-09-14T13:24:22.654Z"},{"affected":"Apache Syncope: 3.0.0-M0 \u2264 3.0.16, 4.0.0-M0 \u2264 4.0.7, 4.1.0-M0 \u2264 4.1.2","affected_versions_present":true,"cve_id":"CVE-2026-73195","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-73195","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-09-14T18:09:01.626Z","patch_url":"","primary_source":"","published":"2026-09-14T13:23:47.800Z"},{"affected":"Apache Syncope: 3.0.0-M0 \u2264 3.0.16, 4.0.0-M0 \u2264 4.0.7, 4.1.0-M0 \u2264 4.1.2","affected_versions_present":true,"cve_id":"CVE-2026-73236","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-73236","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-09-14T19:31:48.348Z","patch_url":"","primary_source":"","published":"2026-09-14T13:23:17.877Z"},{"affected":"Apache Syncope: 3.0.0-M0 \u2264 3.0.16, 4.0.0-M0 \u2264 4.0.7, 4.1.0-M0 \u2264 4.1.2","affected_versions_present":true,"cve_id":"CVE-2026-73370","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-73370","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-09-14T19:30:54.811Z","patch_url":"","primary_source":"","published":"2026-09-14T13:07:58.300Z"},{"affected":"Apache Syncope: 3.0.0-M0 \u2264 3.0.16, 4.0.0-M0 \u2264 4.0.7, 4.1.0-M0 \u2264 4.1.2","affected_versions_present":true,"cve_id":"CVE-2026-73178","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-73178","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-09-14T19:29:51.690Z","patch_url":"","primary_source":"","published":"2026-09-14T13:06:19.901Z"},{"affected":"Apache Syncope: 3.0.0-M0 \u2264 3.0.16, 4.0.0-M0 \u2264 4.0.7, 4.1.0-M0 \u2264 4.1.2","affected_versions_present":true,"cve_id":"CVE-2026-73470","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-73470","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-09-14T19:28:54.807Z","patch_url":"","primary_source":"","published":"2026-09-14T12:58:51.370Z"},{"affected":"Apache Syncope: 3.0.0-M0 \u2264 3.0.16, 4.0.0-M0 \u2264 4.0.7, 4.1.0-M0 \u2264 4.1.2","affected_versions_present":true,"cve_id":"CVE-2026-73579","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-73579","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-09-14T19:27:56.971Z","patch_url":"","primary_source":"","published":"2026-09-14T12:56:31.968Z"},{"affected":"Apache Syncope: 3.0.0-M0 \u2264 3.0.16, 4.0.0-M0 \u2264 4.0.7, 4.1.0-M0 \u2264 4.1.2","affected_versions_present":true,"cve_id":"CVE-2026-75015","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-75015","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-09-14T19:26:59.920Z","patch_url":"","primary_source":"","published":"2026-09-14T12:55:27.674Z"},{"affected":"Apache Syncope: 3.0.0-M0 \u2264 3.0.16, 4.0.0-M0 \u2264 4.0.7, 4.1.0-M0 \u2264 4.1.2","affected_versions_present":true,"cve_id":"CVE-2026-75030","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-75030","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-09-14T19:25:52.804Z","patch_url":"","primary_source":"","published":"2026-09-14T12:54:22.279Z"},{"affected":"Apache Syncope: 3.0.0-M0 \u2264 3.0.16, 4.0.0-M0 \u2264 4.0.7, 4.1.0-M0 \u2264 4.1.2","affected_versions_present":true,"cve_id":"CVE-2026-77051","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-77051","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-09-14T19:25:08.227Z","patch_url":"","primary_source":"","published":"2026-09-14T12:52:49.991Z"},{"affected":"Apache Syncope: 3.0.0-M0 \u2264 3.0.16, 4.0.0-M0 \u2264 4.0.7, 4.1.0-M0 \u2264 4.1.2","affected_versions_present":true,"cve_id":"CVE-2026-73668","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-73668","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-09-14T19:14:24.680Z","patch_url":"","primary_source":"","published":"2026-09-14T12:51:46.076Z"},{"affected":"Apache Syncope: 3.0.0-M0 \u2264 3.0.16, 4.0.0-M0 \u2264 4.0.7, 4.1.0-M0 \u2264 4.1.2","affected_versions_present":true,"cve_id":"CVE-2026-77147","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-77147","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-09-14T18:09:13.433Z","patch_url":"","primary_source":"","published":"2026-09-14T12:49:41.648Z"},{"affected":"Apache Syncope: 3.0.0-M0 \u2264 3.0.16, 4.0.0-M0 \u2264 4.0.7, 4.1.0-M0 \u2264 4.1.2","affected_versions_present":true,"cve_id":"CVE-2026-77181","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-77181","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-09-14T19:15:22.159Z","patch_url":"","primary_source":"","published":"2026-09-14T12:48:01.288Z"},{"affected":"Apache Syncope: 3.0.0-M0 \u2264 3.0.16, 4.0.0-M0 \u2264 4.0.7, 4.1.0-M0 \u2264 4.1.2","affected_versions_present":true,"cve_id":"CVE-2026-77883","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-77883","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-09-14T19:16:45.603Z","patch_url":"","primary_source":"","published":"2026-09-14T12:30:53.819Z"},{"affected":"Apache Syncope: 4.0.4 \u2264 4.0.7, 4.1.0-M0 \u2264 4.1.2","affected_versions_present":true,"cve_id":"CVE-2026-78318","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-78318","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-09-14T19:17:58.065Z","patch_url":"","primary_source":"","published":"2026-09-14T12:29:34.139Z"},{"affected":"Apache Syncope: 3.0.0-M0 \u2264 3.0.16, 4.0.0-M0 \u2264 4.0.7, 4.1.0-M0 \u2264 4.1.2","affected_versions_present":true,"cve_id":"CVE-2026-78330","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-78330","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-09-14T19:20:54.424Z","patch_url":"","primary_source":"","published":"2026-09-14T12:24:56.656Z"},{"affected":"Apache Syncope: 3.0.0-M0 \u2264 3.0.16, 4.0.0-M0 \u2264 4.0.7, 4.1.0-M0 \u2264 4.1.2","affected_versions_present":true,"cve_id":"CVE-2026-78336","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-78336","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-09-14T19:21:38.676Z","patch_url":"","primary_source":"","published":"2026-09-14T12:23:51.971Z"},{"affected":"Apache Syncope: 3.0.0-M0 \u2264 3.0.16, 4.0.0-M0 \u2264 4.0.7, 4.1.0-M0 \u2264 4.1.2","affected_versions_present":true,"cve_id":"CVE-2026-82232","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-82232","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-09-14T19:48:20.965Z","patch_url":"","primary_source":"","published":"2026-09-14T10:45:44.771Z"},{"affected":"Apache Syncope: 3.0.0-M0 \u2264 3.0.16, 4.0.0-M0 \u2264 4.0.7, 4.1.0-M0 \u2264 4.1.2","affected_versions_present":true,"cve_id":"CVE-2026-86460","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-86460","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-09-14T19:47:16.698Z","patch_url":"","primary_source":"","published":"2026-09-14T10:43:58.914Z"},{"affected":"Apache Syncope: 3.0.15 \u2264 3.0.16, 4.0.3 \u2264 4.0.7, 4.1.0-M0 \u2264 4.1.2","affected_versions_present":true,"cve_id":"CVE-2026-87779","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-87779","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-09-14T19:46:26.633Z","patch_url":"","primary_source":"","published":"2026-09-14T10:42:56.292Z"},{"affected":"Apache Syncope: 3.0.0-M0 \u2264 3.0.16, 4.0.0-M0 \u2264 4.0.7, 4.1.0-M0 \u2264 4.1.2","affected_versions_present":true,"cve_id":"CVE-2026-87785","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-87785","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-09-14T19:45:29.921Z","patch_url":"","primary_source":"","published":"2026-09-14T10:38:12.389Z"},{"affected":"Apache Syncope: 3.0.0-M0 \u2264 3.0.16, 4.0.0-M0 \u2264 4.0.7, 4.1.0-M0 \u2264 4.1.2","affected_versions_present":true,"cve_id":"CVE-2026-87802","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-87802","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-09-14T19:39:26.483Z","patch_url":"","primary_source":"","published":"2026-09-14T10:22:29.574Z"},{"affected":"3.0.0-M0 \u2264 3.0.16; 4.0.0-M0 \u2264 4.0.6; 4.1.0-M0 \u2264 4.1.1","affected_versions_present":true,"cve_id":"CVE-2026-62418","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-62418","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-07-21T14:57:00.487Z","patch_url":"","primary_source":"","published":"2026-07-20T14:27:04.679Z"},{"affected":"3.0.0-M0 \u2264 3.0.16; 4.0.0-M0 \u2264 4.0.6; 4.1.0-M0 \u2264 4.1.1","affected_versions_present":true,"cve_id":"CVE-2026-62183","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-62183","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-07-21T14:57:08.107Z","patch_url":"","primary_source":"","published":"2026-07-20T14:23:20.294Z"},{"affected":"3.0.0-M0 \u2264 3.0.16; 4.0.0-M0 \u2264 4.0.6; 4.1.0-M0 \u2264 4.1.1","affected_versions_present":true,"cve_id":"CVE-2026-57308","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-57308","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-07-21T14:57:14.949Z","patch_url":"","primary_source":"","published":"2026-07-20T14:21:57.415Z"},{"affected":"3.0.0-M0 \u2264 3.0.16; 4.0.0-M0 \u2264 4.0.6; 4.1.0-M0 \u2264 4.1.1","affected_versions_present":true,"cve_id":"CVE-2026-53421","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-53421","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-07-21T14:57:20.891Z","patch_url":"","primary_source":"","published":"2026-07-20T14:21:10.071Z"},{"affected":"3.0.0-M0 \u2264 3.0.16; 4.0.0-M0 \u2264 4.0.6; 4.1.0-M0 \u2264 4.1.1","affected_versions_present":true,"cve_id":"CVE-2026-53405","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-53405","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-07-21T14:57:26.644Z","patch_url":"","primary_source":"","published":"2026-07-20T14:20:06.824Z"},{"affected":"3.0.0-M0 \u2264 3.0.16; 4.0.0-M0 \u2264 4.0.6; 4.1.0-M0 \u2264 4.1.1","affected_versions_present":true,"cve_id":"CVE-2026-63071","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-63071","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-07-21T14:57:32.285Z","patch_url":"","primary_source":"","published":"2026-07-20T14:19:19.065Z"},{"affected":"3.0 \u2264 3.0.16; 4.0 \u2264 4.0.5; 4.1 \u2264 4.1.0","affected_versions_present":true,"cve_id":"CVE-2026-42797","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-42797","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-05-26T20:06:31.884Z","patch_url":"","primary_source":"","published":"2026-05-25T15:00:55.670Z"},{"affected":"3.0 \u2264 3.0.16; 4.0 \u2264 4.0.5; 4.1 \u2264 4.1.0","affected_versions_present":true,"cve_id":"CVE-2026-42782","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-42782","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-05-27T20:31:30.996Z","patch_url":"","primary_source":"","published":"2026-05-25T14:58:59.152Z"},{"affected":"3.0 \u2264 3.0.15; 4.0 \u2264 4.0.3","affected_versions_present":true,"cve_id":"CVE-2026-23794","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-23794","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-02-03T16:01:22.030Z","patch_url":"","primary_source":"","published":"2026-02-03T15:15:24.310Z"},{"affected":"3.0 \u2264 3.0.15; 4.0 \u2264 4.0.3","affected_versions_present":true,"cve_id":"CVE-2026-23795","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-23795","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-02-03T16:00:32.112Z","patch_url":"","primary_source":"","published":"2026-02-03T15:14:35.448Z"},{"affected":"2.1 \u2264 2.1.14; 3.0 \u2264 3.0.14; 4.0 \u2264 4.0.2","affected_versions_present":true,"cve_id":"CVE-2025-65998","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-65998","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2025-11-24T15:36:14.583Z","patch_url":"","primary_source":"","published":"2025-11-24T13:47:03.979Z"},{"affected":"2.1 \u2264 2.1.14; 3.0 \u2264 3.0.13; 4.0 \u2264 4.0.1","affected_versions_present":true,"cve_id":"CVE-2025-57738","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-57738","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2025-11-04T21:13:18.181Z","patch_url":"","primary_source":"","published":"2025-10-20T14:43:39.985Z"},{"affected":"2.1 \u2264 2.1.14; 3.0 \u2264 3.0.8","affected_versions_present":true,"cve_id":"CVE-2024-45031","cve_url":"https://cve.blacktree.nl/cve/CVE-2024-45031","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2025-09-01T09:41:29.319Z","patch_url":"","primary_source":"","published":"2024-10-24T14:21:35.279Z"},{"affected":"2.1 \u2264 2.1.14; 3.0 \u2264 3.0.7","affected_versions_present":true,"cve_id":"CVE-2024-38503","cve_url":"https://cve.blacktree.nl/cve/CVE-2024-38503","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2024-12-06T21:48:36.234Z","patch_url":"","primary_source":"","published":"2024-07-22T09:46:39.285Z"},{"affected":"Apache Syncope releases prior to 2.0.11 and 2.1.2","affected_versions_present":true,"cve_id":"CVE-2018-17186","cve_url":"https://cve.blacktree.nl/cve/CVE-2018-17186","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2024-09-17T00:31:30.652Z","patch_url":"https://syncope.apache.org/security#CVE-2018-17186:_XXE_on_BPMN_definitions","primary_source":"","published":"2018-11-06T21:00:00.000Z"},{"affected":"Apache Syncope releases prior to 2.0.11 and 2.1.2","affected_versions_present":true,"cve_id":"CVE-2018-17184","cve_url":"https://cve.blacktree.nl/cve/CVE-2018-17184","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2024-09-17T02:52:18.945Z","patch_url":"","primary_source":"","published":"2018-11-06T19:00:00.000Z"},{"affected":"Releases prior to 1.2.11, Releases prior to 2.0.8; The unsupported Releases 1.0.x, 1.1.x may be also affected.","affected_versions_present":true,"cve_id":"CVE-2018-1322","cve_url":"https://cve.blacktree.nl/cve/CVE-2018-1322","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2024-09-16T17:03:34.787Z","patch_url":"http://syncope.apache.org/security.html#CVE-2018-1322:_Information_disclosure_via_FIQL_and_ORDER_BY_sorting","primary_source":"","published":"2018-03-20T17:00:00.000Z"},{"affected":"Releases prior to 1.2.11, Releases prior to 2.0.8; The unsupported Releases 1.0.x, 1.1.x may be also affected.","affected_versions_present":true,"cve_id":"CVE-2018-1321","cve_url":"https://cve.blacktree.nl/cve/CVE-2018-1321","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2024-09-16T18:03:42.299Z","patch_url":"http://syncope.apache.org/security.html#CVE-2018-1321:_Remote_code_execution_by_administrators_with_report_and_template_entitlements","primary_source":"","published":"2018-03-20T17:00:00.000Z"}],"source_generated_at":"2026-10-05T06:20:29.126Z","vendor":"Apache Software Foundation"}}
