https://seclists.org/oss-sec/2026/q2/852: CVE-2026-25699: Apache Answer: Authorization Bypass in Timeline API
Published Jun 9, 2026
·Updated
Affected Software
1 affected component
Apache Answer<=2.0.0
Frequently Asked Questions
1
What is the severity of CVE-2026-25699?
The severity of CVE-2026-25699 is classified as important.
2
What versions of Apache Answer are affected by CVE-2026-25699?
CVE-2026-25699 affects Apache Answer versions through 2.0.0.
3
What kind of vulnerability is CVE-2026-25699?
CVE-2026-25699 is an authorization bypass vulnerability in the Timeline API.
4
How does CVE-2026-25699 impact user data?
CVE-2026-25699 can lead to exposure of private personal information to unauthorized actors.
5
How can I secure Apache Answer against CVE-2026-25699?
To secure against CVE-2026-25699, you should update Apache Answer to a version above 2.0.0 that includes proper authorization checks.