CVE-2026-48911: Apache Answer: Unauthenticated OAuth Email-Binding Account Takeover via Existing User Confirmation Flow
Insufficient Verification of Data Authenticity vulnerability in Apache Answer.
This issue affects Apache Answer: through 2.0.1.
A missing authorization check in the external-login email binding flow allows unauthenticated attackers to take over arbitrary user accounts by tricking victims into clicking a crafted confirmation link. Users are recommended to upgrade to version 2.0.2, which fixes the issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache Answerto a version that resolves this vulnerability.Fixed in 2.0.2Patch CVE-2026-48911
Event History
Frequently Asked Questions
What is the severity of CVE-2026-48911?
The severity of CVE-2026-48911 is rated at 76.
How do I fix CVE-2026-48911?
To fix CVE-2026-48911, update Apache Answer to version 2.0.2 or later which addresses the missing authorization check.
What systems are affected by CVE-2026-48911?
CVE-2026-48911 affects all versions of Apache Answer up to and including 2.0.1.
What type of attack does CVE-2026-48911 allow?
CVE-2026-48911 allows unauthenticated attackers to take over arbitrary user accounts via an email-binding account takeover attack.
What are the implications of CVE-2026-48911?
CVE-2026-48911 can lead to unauthorized access to user accounts, compromising sensitive information and user privacy.