AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2026-60023

HIGH · CVSS 7.5 EPSS 0.39%

Source: NVD + CISA KEV + EPSS · Published 2026-08-05 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

Apache Answer versions up to 2.0.1 are vulnerable to unauthorized access, allowing attackers to retrieve deleted or pending answers via the single-answer read path if the parent question is still visible. This exposure can lead to the leakage of sensitive information that should remain confidential. Organizations using affected versions should prioritize upgrading to version 2.0.2 to mitigate this risk.

CVE
CVE-2026-60023
Severity
HIGH
CVSS
7.5
EPSS
0.39%
Apache

Original NVD Description

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.1. Deleted or pending answers could be retrieved by unauthorized users through the single-answer read path when the parent question remained visible, exposing answer content that should not have been accessible. Users are recommended to upgrade to version 2.0.2, which fixes the issue.

Related CVEs

Other vulnerabilities affecting the same vendor(s)