https://seclists.org/oss-sec/2026/q3/447: CVE-2026-50749: Apache Answer: Missing authorization in vision audit ject allows authenticated users to ject pending visions
Published Aug 5, 2026
·Updated
Affected Software
1 affected component
Apache Answer<=2.0.1
Frequently Asked Questions
1
What is the severity of CVE-2026-50749?
The severity of CVE-2026-50749 is classified as important.
2
What versions are affected by CVE-2026-50749?
CVE-2026-50749 affects Apache Answer versions through 2.0.1.
3
What is the main issue in CVE-2026-50749?
CVE-2026-50749 involves improper authorization that allows authenticated users to reject pending edit-revisions without appropriate permissions.
4
How do I fix CVE-2026-50749?
To fix CVE-2026-50749, upgrade to a version of Apache Answer later than 2.0.1 that addresses the authorization issue.
5
Who is impacted by CVE-2026-50749?
Any authenticated user of Apache Answer versions through 2.0.1 may be impacted due to the missing authorization controls.