CVE-2026-25699

CVE-2026-25699: Apache Answer: Authorization Bypass in Timeline API

Vendor Apache Software Foundation
Product Apache Answer
Weakness CWE-359
Published June 9, 2026
Last update June 9, 2026

CVSS base score

What the vulnerability does

Description

Exposure of Private Personal Information to an Unauthorized Actor vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. Timeline-related APIs lacked proper authorization checks, allowing regular authenticated users to access deleted, private, or unapproved content and its revision history. Users are recommended to upgrade to version 2.0.1, which fixes the issue.

Key dates

Disclosure timeline

June 9, 2026 CVE published
June 9, 2026 Record updated