Insufficient Session Expiration in Apache Answer - CVE-2026-60053

 

Insufficient Session Expiration in Apache Answer - CVE-2026-60053

Published: August 24, 2026


Vulnerability identifier: #VU144925
CSH Severity: Low
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-60053
CWE-ID: CWE-613
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to retain administrative access.

The vulnerability exists due to insufficient session expiration in administrative API keys when the owning administrator is demoted or the account is marked inactive, suspended, or deleted. A remote user can continue using a previously issued API key to retain administrative access.

The administrative API keys remain usable until they are explicitly removed.


Affected software

Apache Answer

How to mitigate CVE-2026-60053

Install security update from vendor's website.

Apache Answer - update to 2.0.2

External References

Related Security Bulletins