CVE-2026-48912
MEDIUMApache Answer <= 2.0.1 - Authenticated Avatar File Deletion
Title source: manualDescription
Improper Input Validation vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.1. A missing ownership check in the avatar-cleanup logic allows any authenticated user to delete other users' uploaded files by supplying their file URLs. Users are recommended to upgrade to version 2.0.2, which fixes the issue.
References (2)
Core 2
Core References
Vendor Advisory vendor-advisory
https://lists.apache.org/thread/b9jnttmspd9kp4vgbvb32dcqb4201flq
Mailing List, Third Party Advisory
http://www.openwall.com/lists/oss-security/2026/08/05/11
Scores
CVSS v3
6.5
EPSS
0.0031
EPSS Percentile
22.9%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-639
Status
published
Products (2)
apache/answer
< 2.0.2
Apache Software Foundation/Apache Answer
< 2.0.1
Published
Aug 05, 2026
Tracked Since
Aug 05, 2026