Improper access control in Apache Answer - CVE-2026-34905

 

Improper access control in Apache Answer - CVE-2026-34905

Published: August 25, 2026


Vulnerability identifier: #VU145213
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-34905
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to disclose sensitive information.

The vulnerability exists due to improper access control in direct API endpoints for unlisted questions when handling authenticated API requests. A remote user can send crafted API requests to disclose sensitive information.

Accessible data may include unlisted questions, their answers, comments, and revision history.


Affected software

Apache Answer

How to mitigate CVE-2026-34905

Install security update from vendor's website.

Apache Answer - update to 2.0.1

External References

Related Security Bulletins