CVE-2026-60023

CVE-2026-60023: Apache Answer: Unauthorized disclosure of deleted or pending answer content

Vendor Apache Software Foundation
Product Apache Answer
Weakness CWE-200 · Info exposure
Published August 5, 2026
Last update August 5, 2026

CVSS base score

What the vulnerability does

01Description

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.1. Deleted or pending answers could be retrieved by unauthorized users through the single-answer read path when the parent question remained visible, exposing answer content that should not have been accessible. Users are recommended to upgrade to version 2.0.2, which fixes the issue.

Key dates

02Disclosure timeline

August 5, 2026 CVE published

Related vulnerabilities

04Related CVE