CVE-2026-24735
HIGHApache Answer <2.0.0 - Info Disclosure
Title source: llmDescription
Exposure of Private Personal Information to an Unauthorized Actor vulnerability in Apache Answer. This issue affects Apache Answer: through 1.7.1. An unauthenticated API endpoint incorrectly exposes full revision history for deleted content. This allows unauthorized user to retrieve restricted or sensitive information. Users are recommended to upgrade to version 2.0.0, which fixes the issue.
Scores
CVSS v3
7.5
EPSS
0.0003
EPSS Percentile
6.5%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Classification
CWE
CWE-359
Status
published
Affected Products (2)
apache/answer
< 2.0.0
apache/answer
< 2.0.0Go
Timeline
Published
Feb 04, 2026
Tracked Since
Feb 18, 2026