AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2026-48912

MEDIUM · CVSS 6.5 EPSS 0.30%

Source: NVD + CISA KEV + EPSS · Published 2026-08-05 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

Apache Answer versions up to 2.0.1 are vulnerable due to improper input validation, allowing authenticated users to delete other users' uploaded files by manipulating file URLs. This poses a significant risk to data integrity and user privacy. Organizations using affected versions should prioritize upgrading to version 2.0.2 to mitigate this vulnerability.

CVE
CVE-2026-48912
Severity
MEDIUM
CVSS
6.5
EPSS
0.30%
Apache

Original NVD Description

Improper Input Validation vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.1. A missing ownership check in the avatar-cleanup logic allows any authenticated user to delete other users' uploaded files by supplying their file URLs. Users are recommended to upgrade to version 2.0.2, which fixes the issue.

Related CVEs

Other vulnerabilities affecting the same vendor(s)