Improper access control in Apache Answer - CVE-2026-34905
Published: August 25, 2026
Vulnerability details
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to improper access control in direct API endpoints for unlisted questions when handling authenticated API requests. A remote user can send crafted API requests to disclose sensitive information.
Accessible data may include unlisted questions, their answers, comments, and revision history.