LIVE · cybersecurity feed
Live wire
cve recordhigh

CVE-2026-25700

apache · answer

Published
CVSS7.2
Severityhigh
WeaknessCWE-1259
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Description

Improper Restriction of Security Token Assignment vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. Previously issued administrative tokens were not invalidated after an administrator account was suspended, deleted, or deactivated, allowing continued access to administrative APIs until the token expired. Users are recommended to upgrade to version 2.0.1, which fixes the issue.

References

← Back to the CVE Tracker

Our coverage of CVE-2026-25700

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-25700.