CVE-2026-50749

CVE-2026-50749: Apache Answer: Missing authorization in revision audit reject allows authenticated users to reject pending revisions

Vendor Apache Software Foundation
Product Apache Answer
Weakness CWE-863 · Incorrect authorization
Published August 5, 2026
Last update August 6, 2026

CVSS base score

What the vulnerability does

01Description

Improper Authorization vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.1. Any authenticated user can reject arbitrary pending edit-revisions without review permission due to a missing authorization check on the reject operation. Users are recommended to upgrade to version 2.0.2, which fixes the issue.

Key dates

02Disclosure timeline

August 5, 2026 CVE published
August 6, 2026 Record updated

Related vulnerabilities

04Related CVE