Improper access control in Apache Answer - CVE-2026-25699
Published: August 25, 2026
Vulnerability details
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to improper access control in timeline-related APIs when handling requests for timeline content and revision history. A remote user can request deleted, private, or unapproved content and its revision history to disclose sensitive information.
The issue affects regular authenticated users accessing content that should not be available to them.