Insufficient Session Expiration in Apache Answer - CVE-2026-60053
Published: August 24, 2026
Vulnerability details
The vulnerability allows a remote user to retain administrative access.
The vulnerability exists due to insufficient session expiration in administrative API keys when the owning administrator is demoted or the account is marked inactive, suspended, or deleted. A remote user can continue using a previously issued API key to retain administrative access.
The administrative API keys remain usable until they are explicitly removed.