SB20260824199 - Multiple vulnerabilities in Apache Answer



SB20260824199 - Multiple vulnerabilities in Apache Answer

Published: August 24, 2026

Security Bulletin ID SB20260824199
CSH Severity
High
Patch available
YES
Number of vulnerabilities 6
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

High 17% Medium 33% Low 50%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 6 vulnerabilities.


1) Improper Handling of Length Parameter Inconsistency (CVE-ID: CVE-2026-48834)

CWE-ID: CWE-130 - Improper Handling of Length Parameter Inconsistency

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to improper handling of length parameter inconsistency in Accept-Language header parsing when handling a specially crafted Accept-Language header. A remote attacker can send a specially crafted Accept-Language header to cause a denial of service.

The issue triggers excessive CPU consumption during parsing.


2) Insufficient verification of data authenticity (CVE-ID: CVE-2026-48911)

CWE-ID: CWE-345 - Insufficient Verification of Data Authenticity

CVSSv4: 8.3 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to take over arbitrary user accounts.

The vulnerability exists due to insufficient verification of data authenticity in the external-login email binding flow when processing crafted confirmation links. A remote attacker can trick a victim into clicking a crafted confirmation link to take over arbitrary user accounts.

User interaction is required to click the crafted confirmation link.


3) Improper access control (CVE-ID: CVE-2026-48912)

CWE-ID: CWE-284 - Improper Access Control

CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to delete arbitrary uploaded files.

The vulnerability exists due to improper access control in the avatar-cleanup logic when processing avatar update requests with user-supplied file URLs. A remote user can supply a file URL belonging to another user to delete arbitrary uploaded files.


4) Improper Authorization (CVE-ID: CVE-2026-50749)

CWE-ID: CWE-285 - Improper Authorization

CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to reject arbitrary pending edit revisions.

The vulnerability exists due to improper authorization in the revision audit reject operation when handling revision rejection requests. A remote user can submit a reject operation without review permission to reject arbitrary pending edit revisions.


5) Improper access control (CVE-ID: CVE-2026-60023)

CWE-ID: CWE-284 - Improper Access Control

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to improper access control in the single-answer read path when retrieving deleted or pending answers whose parent question remains visible. A remote attacker can request a single answer record to disclose sensitive information.

Only answers in deleted or pending state are exposed when their parent question is still visible.


6) Insufficient Session Expiration (CVE-ID: CVE-2026-60053)

CWE-ID: CWE-613 - Insufficient Session Expiration

CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to retain administrative access.

The vulnerability exists due to insufficient session expiration in administrative API keys when the owning administrator is demoted or the account is marked inactive, suspended, or deleted. A remote user can continue using a previously issued API key to retain administrative access.

The administrative API keys remain usable until they are explicitly removed.


Remediation

Install update from vendor's website.