CVE-2026-25699
MEDIUMApache Answer: Authorization Bypass in Timeline API
Title source: cnaDescription
Exposure of Private Personal Information to an Unauthorized Actor vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. Timeline-related APIs lacked proper authorization checks, allowing regular authenticated users to access deleted, private, or unapproved content and its revision history. Users are recommended to upgrade to version 2.0.1, which fixes the issue.
References (2)
Core 2
Core References
Vendor Advisory vendor-advisory
https://lists.apache.org/thread/c36k4hzwhncqo0qfn5fg57f1gkjhyfv8
Scores
CVSS v3
6.1
EPSS
0.0036
EPSS Percentile
27.3%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-359
Status
published
Products (2)
apache/answer
< 2.0.1
Apache Software Foundation/Apache Answer
< 2.0.0
Published
Jun 09, 2026
Tracked Since
Jun 09, 2026