Insufficient Verification of Data Authenticity in Apache Answer - Apache
CVE-2026-48911
Currently unrated
What is CVE-2026-48911?
A security flaw has been identified in Apache Answer that poses a risk of unauthorized user account access. Specifically, a missing authorization check in the external-login email binding flow allows unauthenticated attackers to potentially seize control of user accounts by deceiving victims into clicking a malicious confirmation link. It is crucial for users to upgrade to version 2.0.2, which mitigates this vulnerability and enhances overall security.
Affected Version(s)
Apache Answer 0 <= 2.0.1