Insufficient Verification of Data Authenticity in Apache Answer - Apache
CVE-2026-48911

Currently unrated

Key Information:

Vendor

Apache

Vendor
CVE Published:
5 August 2026

What is CVE-2026-48911?

A security flaw has been identified in Apache Answer that poses a risk of unauthorized user account access. Specifically, a missing authorization check in the external-login email binding flow allows unauthenticated attackers to potentially seize control of user accounts by deceiving victims into clicking a malicious confirmation link. It is crucial for users to upgrade to version 2.0.2, which mitigates this vulnerability and enhances overall security.

Affected Version(s)

Apache Answer 0 <= 2.0.1

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

tonghuaroot
yangxi
.