Insufficient verification of data authenticity in Apache Answer - CVE-2026-48911
Published: August 24, 2026
Vulnerability details
The vulnerability allows a remote attacker to take over arbitrary user accounts.
The vulnerability exists due to insufficient verification of data authenticity in the external-login email binding flow when processing crafted confirmation links. A remote attacker can trick a victim into clicking a crafted confirmation link to take over arbitrary user accounts.
User interaction is required to click the crafted confirmation link.