SB2026082571 - Multiple vulnerabilities in Apache Answer



SB2026082571 - Multiple vulnerabilities in Apache Answer

Published: August 25, 2026

Security Bulletin ID SB2026082571
CSH Severity
Medium
Patch available
YES
Number of vulnerabilities 7
Exploitation vector Remote access
Highest impact Denial of service

Breakdown by Severity

Medium 14% Low 86%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 7 vulnerabilities.


1) Improper access control (CVE-ID: CVE-2026-34905)

CWE-ID: CWE-284 - Improper Access Control

CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to disclose sensitive information.

The vulnerability exists due to improper access control in direct API endpoints for unlisted questions when handling authenticated API requests. A remote user can send crafted API requests to disclose sensitive information.

Accessible data may include unlisted questions, their answers, comments, and revision history.


2) Cross-site scripting (CVE-ID: CVE-2026-34033)

CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]


The vulnerability allows a remote user to inject arbitrary HTML into notification emails sent to other users.

The vulnerability exists due to improper neutralization of script-related html tags in notification emails when including user-supplied content. A remote user can submit crafted content to inject arbitrary HTML into notification emails sent to other users.


3) Input validation error (CVE-ID: CVE-2026-34031)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 4.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to disclose sensitive information.

The vulnerability exists due to improper validation of user-supplied URLs in custom avatar handling when processing profile image URLs. A remote user can supply a crafted external image URL to disclose sensitive information.

This can cause victims' browsers to make unintended requests to third-party servers, enabling external tracking.


4) Uncontrolled Memory Allocation (CVE-ID: CVE-2026-33582)

CWE-ID: CWE-789 - Uncontrolled Memory Allocation

CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to cause a denial of service.

The vulnerability exists due to uncontrolled memory allocation in image decoding when processing uploaded TIFF files. A remote user can upload a specially crafted TIFF file to cause a denial of service.


5) Improper access control (CVE-ID: CVE-2026-25699)

CWE-ID: CWE-284 - Improper Access Control

CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to disclose sensitive information.

The vulnerability exists due to improper access control in timeline-related APIs when handling requests for timeline content and revision history. A remote user can request deleted, private, or unapproved content and its revision history to disclose sensitive information.

The issue affects regular authenticated users accessing content that should not be available to them.


6) Cross-site scripting (CVE-ID: CVE-2026-25688)

CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]


The vulnerability allows a remote attacker to execute arbitrary script code in the victim's browser.

The vulnerability exists due to improper neutralization of alternate xss syntax in AI answer rendering when rendering AI-generated response content in the browser. A remote attacker can craft malicious AI-generated content to execute arbitrary script code in the victim's browser.

User interaction is required to view the crafted content.


7) Incorrect Privilege Assignment (CVE-ID: CVE-2026-25700)

CWE-ID: CWE-266 - Incorrect Privilege Assignment

CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to access administrative APIs.

The vulnerability exists due to improper restriction of security token assignment in administrative token handling when an administrator account is suspended, deleted, or deactivated. A remote user can continue using a previously issued administrative token to access administrative APIs.

Access continues until the token expires.


Remediation

Install update from vendor's website.