CVE-2026-50749: Apache Answer: Missing authorization in revision audit reject allows authenticated users to reject pending revisions
Improper Authorization vulnerability in Apache Answer.
This issue affects Apache Answer: through 2.0.1.
Any authenticated user can reject arbitrary pending edit-revisions without review permission due to a missing authorization check on the reject operation. Users are recommended to upgrade to version 2.0.2, which fixes the issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache Answerto a version that resolves this vulnerability.Fixed in 2.0.2
Event History
Frequently Asked Questions
What is the severity of CVE-2026-50749?
CVE-2026-50749 has a risk score of 35, indicating a significant vulnerability.
How do I fix CVE-2026-50749?
To address CVE-2026-50749, users should upgrade to Apache Answer version 2.0.2 or later.
What type of vulnerability is CVE-2026-50749?
CVE-2026-50749 is categorized as an Improper Authorization vulnerability.
Who is affected by CVE-2026-50749?
CVE-2026-50749 affects all users of Apache Answer up to version 2.0.1.
What can unauthorized users do in CVE-2026-50749?
In the context of CVE-2026-50749, any authenticated user can reject arbitrary pending edit-revisions without proper permissions.