Exposure of Sensitive Information in Apache Answer by Apache
CVE-2026-60023
Currently unrated
What is CVE-2026-60023?
The Apache Answer product is susceptible to an exposure of sensitive information vulnerability that allows unauthorized users to retrieve deleted or pending answers via the single-answer read path. This issue occurs when the parent question remains visible, giving access to content that should otherwise be protected. To safeguard sensitive information, users are strongly advised to upgrade to version 2.0.2, where this vulnerability has been resolved.
Affected Version(s)
Apache Answer 0 <= 2.0.1