Incorrect Privilege Assignment in Apache Answer - CVE-2026-25700
Published: August 25, 2026
Vulnerability details
The vulnerability allows a remote user to access administrative APIs.
The vulnerability exists due to improper restriction of security token assignment in administrative token handling when an administrator account is suspended, deleted, or deactivated. A remote user can continue using a previously issued administrative token to access administrative APIs.
Access continues until the token expires.