AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2026-48911

HIGH · CVSS 7.5 EPSS 0.37%

Source: NVD + CISA KEV + EPSS · Published 2026-08-05 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

Apache Answer versions up to 2.0.1 are vulnerable due to a missing authorization check in the external-login email binding flow, allowing unauthenticated attackers to hijack user accounts via a crafted confirmation link. Organizations using this software should prioritize upgrading to version 2.0.2 to mitigate the risk of account takeover.

CVE
CVE-2026-48911
Severity
HIGH
CVSS
7.5
EPSS
0.37%
Apache

Original NVD Description

Insufficient Verification of Data Authenticity vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.1. A missing authorization check in the external-login email binding flow allows unauthenticated attackers to take over arbitrary user accounts by tricking victims into clicking a crafted confirmation link. Users are recommended to upgrade to version 2.0.2, which fixes the issue.

Related CVEs

Other vulnerabilities affecting the same vendor(s)