LIVE · cybersecurity feed
Live wire
cve recordhigh

CVE-2026-60023

apache · answer

Published
CVSS7.5
Severityhigh
WeaknessCWE-200
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Description

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.1. Deleted or pending answers could be retrieved by unauthorized users through the single-answer read path when the parent question remained visible, exposing answer content that should not have been accessible. Users are recommended to upgrade to version 2.0.2, which fixes the issue.

References

← Back to the CVE Tracker

Our coverage of CVE-2026-60023

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-60023.