Severity: important 

Affected versions:

- Apache Answer through 2.0.0

Description:

Improper Restriction of Security Token Assignment vulnerability in Apache 
Answer.

This issue affects Apache Answer: through 2.0.0.

Previously issued administrative tokens were not invalidated after an 
administrator account was suspended, deleted, or deactivated, allowing 
continued access to administrative APIs until the token expired.
Users are recommended to upgrade to version 2.0.1, which fixes the issue.

Credit:

Sho Odagiri (reporter)

References:

https://answer.apache.org
https://www.cve.org/CVERecord?id=CVE-2026-25700

Reply via email to