Improper access control in Apache Answer - CVE-2026-60023
Published: August 24, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to improper access control in the single-answer read path when retrieving deleted or pending answers whose parent question remains visible. A remote attacker can request a single answer record to disclose sensitive information.
Only answers in deleted or pending state are exposed when their parent question is still visible.