Exposure of Private Personal Information to an Unauthorized Actor vulnerability in Apache Answer.
This issue affects Apache Answer: through 1.7.1.
An unauthenticated API endpoint incorrectly exposes full revision history for deleted content. This allows unauthorized user to retrieve restricted or sensitive information.
Users are recommended to upgrade to version 2.0.0, which fixes the issue.
References
| Link | Resource |
|---|---|
| https://lists.apache.org/thread/whxloom7mpxlyt5wzdskflsg5mzdzd60 | Mailing List Third Party Advisory |
| http://www.openwall.com/lists/oss-security/2026/02/04/1 | Mailing List Third Party Advisory |
Configurations
History
06 Feb 2026, 14:40
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://lists.apache.org/thread/whxloom7mpxlyt5wzdskflsg5mzdzd60 - Mailing List, Third Party Advisory | |
| References | () http://www.openwall.com/lists/oss-security/2026/02/04/1 - Mailing List, Third Party Advisory | |
| First Time |
Apache answer
Apache |
|
| CPE | cpe:2.3:a:apache:answer:*:*:*:*:*:*:*:* |
04 Feb 2026, 19:16
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
04 Feb 2026, 16:16
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.5 |
04 Feb 2026, 11:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-02-04 11:16
Updated : 2026-02-06 14:40
NVD link : CVE-2026-24735
Mitre link : CVE-2026-24735
CVE.ORG link : CVE-2026-24735
JSON object : View
Products Affected
apache
- answer
CWE
CWE-359
Exposure of Private Personal Information to an Unauthorized Actor
