Exposure of Sensitive Information in Apache Answer by Apache
CVE-2026-60023

Currently unrated

Key Information:

Vendor

Apache

Vendor
CVE Published:
5 August 2026

What is CVE-2026-60023?

The Apache Answer product is susceptible to an exposure of sensitive information vulnerability that allows unauthorized users to retrieve deleted or pending answers via the single-answer read path. This issue occurs when the parent question remains visible, giving access to content that should otherwise be protected. To safeguard sensitive information, users are strongly advised to upgrade to version 2.0.2, where this vulnerability has been resolved.

Affected Version(s)

Apache Answer 0 <= 2.0.1

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

yangxi
.