Improper Input Validation in Apache Answer by Apache
CVE-2026-48912

Currently unrated

Key Information:

Vendor

Apache

Vendor
CVE Published:
5 August 2026

What is CVE-2026-48912?

An improper input validation vulnerability exists in Apache Answer, specifically impacting version 2.0.1. This flaw allows authenticated users to bypass ownership checks during the avatar-cleanup process, potentially leading to unauthorized deletion of other users' uploaded files by manipulating their file URLs. Users are strongly encouraged to upgrade to version 2.0.2 to mitigate this risk and safeguard their data.

Affected Version(s)

Apache Answer 0 <= 2.0.1

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

tonghuaroot
.