Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Answer.
This issue affects Apache Answer: through 2.0.0.
The unlisted question feature did not enforce access restrictions on direct API endpoints, allowing authenticated users to discover and access unlisted questions, their answers, comments, and revision history.
Users are recommended to upgrade to version 2.0.1, which fixes the issue.
References
| Link | Resource |
|---|---|
| https://lists.apache.org/thread/khxoft96sptr2kh0cpzgw7f6qwv0ltcf | Mailing List Third Party Advisory |
| http://www.openwall.com/lists/oss-security/2026/06/09/2 | Issue Tracking |
Configurations
History
10 Jun 2026, 13:28
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Apache
Apache answer |
|
| CPE | cpe:2.3:a:apache:answer:*:*:*:*:*:*:*:* | |
| References | () https://lists.apache.org/thread/khxoft96sptr2kh0cpzgw7f6qwv0ltcf - Mailing List, Third Party Advisory | |
| References | () http://www.openwall.com/lists/oss-security/2026/06/09/2 - Issue Tracking |
09 Jun 2026, 16:16
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.5 |
09 Jun 2026, 10:16
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
09 Jun 2026, 09:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-06-09 09:16
Updated : 2026-06-10 13:28
NVD link : CVE-2026-34905
Mitre link : CVE-2026-34905
CVE.ORG link : CVE-2026-34905
JSON object : View
Products Affected
apache
- answer
CWE
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor
