Improper access control in Apache Answer - CVE-2026-60023

 

Improper access control in Apache Answer - CVE-2026-60023

Published: August 24, 2026


Vulnerability identifier: #VU144924
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-60023
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to improper access control in the single-answer read path when retrieving deleted or pending answers whose parent question remains visible. A remote attacker can request a single answer record to disclose sensitive information.

Only answers in deleted or pending state are exposed when their parent question is still visible.


Affected software

Apache Answer

How to mitigate CVE-2026-60023

Install security update from vendor's website.

Apache Answer - update to 2.0.2

External References

Related Security Bulletins