https://seclists.org/oss-sec/2026/q2/871: CVE-2026-25700: Apache Answer: AdminToken not invalidated after admin deactivation
Published Jun 10, 2026
·Updated
Affected Software
1 affected component
Apache Answer<=2.0.0
Frequently Asked Questions
1
What is the severity of CVE-2026-25700?
The severity of CVE-2026-25700 is classified as important.
2
What versions are affected by CVE-2026-25700?
Apache Answer versions through 2.0.0 are affected by CVE-2026-25700.
3
What is the main issue addressed in CVE-2026-25700?
CVE-2026-25700 addresses the improper restriction of security token assignment where admin tokens were not invalidated after admin deactivation.
4
How do I fix CVE-2026-25700?
To fix CVE-2026-25700, update Apache Answer to a version beyond 2.0.0 where this vulnerability is resolved.
5
What can happen if CVE-2026-25700 is exploited?
Exploitation of CVE-2026-25700 could allow unauthorized access to administrative privileges due to invalidated tokens.