CVE-2026-48911

CVE-2026-48911: Apache Answer: Unauthenticated OAuth Email-Binding Account Takeover via Existing User Confirmation Flow

Vendor Apache Software Foundation
Product Apache Answer
Weakness CWE-306 · Missing auth
Published August 5, 2026
Last update August 5, 2026

CVSS base score

What the vulnerability does

01Description

Insufficient Verification of Data Authenticity vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.1. A missing authorization check in the external-login email binding flow allows unauthenticated attackers to take over arbitrary user accounts by tricking victims into clicking a crafted confirmation link. Users are recommended to upgrade to version 2.0.2, which fixes the issue.

Key dates

02Disclosure timeline

August 5, 2026 CVE published

Related vulnerabilities

04Related CVE