CVE-2026-34905: Apache Answer: Unlisted Questions Accessible via Direct API Access
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Answer.
This issue affects Apache Answer: through 2.0.0.
The unlisted question feature did not enforce access restrictions on direct API endpoints, allowing authenticated users to discover and access unlisted questions, their answers, comments, and revision history. Users are recommended to upgrade to version 2.0.1, which fixes the issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache Answerto a version that resolves this vulnerability.Fixed in 2.0.1
Event History
Frequently Asked Questions
What is the severity of CVE-2026-34905?
The severity of CVE-2026-34905 is medium with a CVSS score of 6.5.
How do I fix CVE-2026-34905?
To fix CVE-2026-34905, ensure that access restrictions are enforced on all direct API endpoints in Apache Answer.
What does CVE-2026-34905 expose?
CVE-2026-34905 exposes unlisted questions to unauthorized users through an accessible direct API.
Which versions of Apache Answer are affected by CVE-2026-34905?
CVE-2026-34905 affects Apache Answer versions up to and including 2.0.0.
What kind of vulnerability is CVE-2026-34905 classified as?
CVE-2026-34905 is classified as an information leak vulnerability.