CVE-2026-48912: Apache Answer: Improper authorization in avatar update cleanup allows authenticated users to delete arbitrary uploaded files by URL
Improper Input Validation vulnerability in Apache Answer.
This issue affects Apache Answer: through 2.0.1.
A missing ownership check in the avatar-cleanup logic allows any authenticated user to delete other users' uploaded files by supplying their file URLs. Users are recommended to upgrade to version 2.0.2, which fixes the issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache Answerto a version that resolves this vulnerability.Fixed in 2.0.2Patch CVE-2026-48912
Event History
Frequently Asked Questions
What is the severity of CVE-2026-48912?
The severity of CVE-2026-48912 is rated at 35.
How do I fix CVE-2026-48912?
To fix CVE-2026-48912, users should upgrade to a version of Apache Answer that is later than 2.0.1.
What effect does CVE-2026-48912 have on system security?
CVE-2026-48912 allows authenticated users to delete arbitrary uploaded files, posing a significant risk to user data.
Which versions of Apache are affected by CVE-2026-48912?
CVE-2026-48912 affects Apache Answer versions up to and including 2.0.1.
What type of vulnerability is CVE-2026-48912?
CVE-2026-48912 is classified as an Improper Input Validation vulnerability.