PT-2026-47713 · Apache · Apache Answer

·

CVE-2026-25699

·

Published

2026-06-09

·

Updated

2026-06-10

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Apache Answer versions prior to 2.0.1
Description Timeline-related APIs lack proper authorization checks, which allows authenticated users to access content that is private, deleted, or unapproved, as well as its associated revision history. This leads to the exposure of private personal information to unauthorized actors.
Recommendations Upgrade to version 2.0.1.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-25699
GHSA-W754-5646-XQ9J

Affected Products

Apache Answer