Improper Authorization Vulnerability in Apache Answer Product by Apache
CVE-2026-50749

Currently unrated

Key Information:

Vendor

Apache

Vendor
CVE Published:
5 August 2026

What is CVE-2026-50749?

The Apache Answer software suffers from an improper authorization vulnerability that allows authenticated users to reject pending edit-revisions without having the necessary review permissions. This flaw emerges due to the absence of an appropriate authorization check during the reject operation, posing a risk of unauthorized modification. Users are advised to upgrade to version 2.0.2 to address this security concern and ensure robust user permissions.

Affected Version(s)

Apache Answer 0 <= 2.0.1

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

tonghuaroot
Mattia Campanelli
Cavan Loughran
Xi Yang
.