Severity: important 

Affected versions:

- Apache Answer through 2.0.0

Description:

Exposure of Private Personal Information to an Unauthorized Actor vulnerability 
in Apache Answer.

This issue affects Apache Answer: through 2.0.0.

Timeline-related APIs lacked proper authorization checks, allowing regular 
authenticated users to access deleted, private, or unapproved content and its 
revision history.
Users are recommended to upgrade to version 2.0.1, which fixes the issue.

Credit:

Sho Odagiri (reporter)

References:

https://answer.apache.org
https://www.cve.org/CVERecord?id=CVE-2026-25699

Reply via email to