Improper Input Validation in Apache Answer by Apache
CVE-2026-48912
Currently unrated
What is CVE-2026-48912?
An improper input validation vulnerability exists in Apache Answer, specifically impacting version 2.0.1. This flaw allows authenticated users to bypass ownership checks during the avatar-cleanup process, potentially leading to unauthorized deletion of other users' uploaded files by manipulating their file URLs. Users are strongly encouraged to upgrade to version 2.0.2 to mitigate this risk and safeguard their data.
Affected Version(s)
Apache Answer 0 <= 2.0.1