CVE-2026-24735: Apache Answer: Revision API Improper Access Control leads to Information Disclosure
Exposure of Private Personal Information to an Unauthorized Actor vulnerability in Apache Answer.
This issue affects Apache Answer: through 1.7.1.
An unauthenticated API endpoint incorrectly exposes full revision history for deleted content. This allows unauthorized user to retrieve restricted or sensitive information. Users are recommended to upgrade to version 2.0.0, which fixes the issue.
Other sources
Exposure of Private Personal Information to an Unauthorized Actor vulnerability in Apache Answer.
This issue affects Apache Answer: through 1.7.1.
An unauthenticated API endpoint incorrectly exposes full revision history for deleted content. This allows unauthorized users to retrieve restricted or sensitive information. Users are recommended to upgrade to version 2.0.0, which fixes the issue.
— GitHub
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-24735?
The severity of CVE-2026-24735 is classified as a moderate risk due to the exposure of private personal information.
How do I fix CVE-2026-24735?
To fix CVE-2026-24735, upgrade Apache Answer to version 1.7.2 or later where the issue is resolved.
What versions of Apache Answer are affected by CVE-2026-24735?
CVE-2026-24735 affects Apache Answer versions up to and including 1.7.1.
What type of vulnerability is CVE-2026-24735?
CVE-2026-24735 is an improper access control vulnerability that leads to information disclosure.
Who can be affected by CVE-2026-24735?
Any user of Apache Answer prior to version 1.7.2 can be affected by CVE-2026-24735, as it allows unauthorized access to sensitive information.