AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2026-50749

MEDIUM · CVSS 6.5 EPSS 0.30%

Source: NVD + CISA KEV + EPSS · Published 2026-08-05 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

Apache Answer versions up to 2.0.1 are vulnerable to an improper authorization flaw that allows any authenticated user to reject pending edit-revisions without the necessary review permissions. This could lead to unauthorized changes and potential disruption of content management processes. Organizations using affected versions should prioritize upgrading to version 2.0.2 to mitigate this risk.

CVE
CVE-2026-50749
Severity
MEDIUM
CVSS
6.5
EPSS
0.30%
Apache

Original NVD Description

Improper Authorization vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.1. Any authenticated user can reject arbitrary pending edit-revisions without review permission due to a missing authorization check on the reject operation. Users are recommended to upgrade to version 2.0.2, which fixes the issue.

Related CVEs

Other vulnerabilities affecting the same vendor(s)