CVE-2026-25699: Apache Answer: Authorization Bypass in Timeline API
Exposure of Private Personal Information to an Unauthorized Actor vulnerability in Apache Answer.
This issue affects Apache Answer: through 2.0.0.
Timeline-related APIs lacked proper authorization checks, allowing regular authenticated users to access deleted, private, or unapproved content and its revision history. Users are recommended to upgrade to version 2.0.1, which fixes the issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache Answerto a version that resolves this vulnerability.Fixed in 2.0.1
Event History
Frequently Asked Questions
What is the severity of CVE-2026-25699?
CVE-2026-25699 has a medium severity rating of 6.1.
How do I fix CVE-2026-25699?
To fix CVE-2026-25699, ensure that proper authorization checks are implemented in the Timeline API of Apache Answer.
What impact does CVE-2026-25699 have?
CVE-2026-25699 allows unauthorized users to access deleted or private content, leading to potential exposure of personal information.
Which versions of Apache Answer are affected by CVE-2026-25699?
CVE-2026-25699 affects all versions of Apache Answer up to and including 2.0.0.
Can CVE-2026-25699 be exploited remotely?
Yes, CVE-2026-25699 can be exploited remotely due to the nature of the authorization bypass in the Timeline API.