CVE-2026-34905
MEDIUMApache Answer: Unlisted Questions Accessible via Direct API Access
Title source: cnaDescription
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. The unlisted question feature did not enforce access restrictions on direct API endpoints, allowing authenticated users to discover and access unlisted questions, their answers, comments, and revision history. Users are recommended to upgrade to version 2.0.1, which fixes the issue.
References (2)
Core 2
Core References
Vendor Advisory vendor-advisory
https://lists.apache.org/thread/khxoft96sptr2kh0cpzgw7f6qwv0ltcf
Scores
CVSS v3
6.5
EPSS
0.0032
EPSS Percentile
24.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-200
Status
published
Products (2)
apache/answer
< 2.0.1
Apache Software Foundation/Apache Answer
< 2.0.0
Published
Jun 09, 2026
Tracked Since
Jun 09, 2026