CVE-2026-48912

MEDIUM

Apache Answer <= 2.0.1 - Authenticated Avatar File Deletion

Title source: manual
STIX 2.1

Description

Improper Input Validation vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.1. A missing ownership check in the avatar-cleanup logic allows any authenticated user to delete other users' uploaded files by supplying their file URLs. Users are recommended to upgrade to version 2.0.2, which fixes the issue.

References (2)

Core 2
Core References

Scores

CVSS v3 6.5
EPSS 0.0031
EPSS Percentile 22.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-639
Status published
Products (2)
apache/answer < 2.0.2
Apache Software Foundation/Apache Answer < 2.0.1
Published Aug 05, 2026
Tracked Since Aug 05, 2026