https://seclists.org/oss-sec/2026/q2/848: CVE-2026-34905: Apache Answer: Unlisted Questions Accessible via Dict API Access
Published Jun 9, 2026
·Updated
Affected Software
1 affected component
Apache Answer<=2.0.0
Frequently Asked Questions
1
What is the severity of CVE-2026-34905?
The severity of CVE-2026-34905 is classified as moderate.
2
Which versions of Apache Answer are affected by CVE-2026-34905?
CVE-2026-34905 affects Apache Answer versions through 2.0.0.
3
What is CVE-2026-34905 about?
CVE-2026-34905 describes an exposure of sensitive information to an unauthorized actor via the unlisted question feature in Apache Answer.
4
How do I fix CVE-2026-34905?
To fix CVE-2026-34905, upgrade to a version of Apache Answer later than 2.0.0 that includes the necessary security patches.
5
What type of vulnerability is CVE-2026-34905?
CVE-2026-34905 is categorized as a vulnerability that exposes sensitive information due to insufficient access restrictions.