Insufficient Session Expiration in Apache Answer Affects Admin Access
CVE-2026-60053
Currently unrated
What is CVE-2026-60053?
The insufficient session expiration vulnerability in Apache Answer allows administrative API keys to remain functional even after an administrator's account has been demoted, marked inactive, suspended, or deleted. This flaw grants unauthorized continued access to the API, posing a significant security risk. Users are encouraged to upgrade to version 2.0.2 to patch this issue, ensuring that administrative access is properly revoked when account statuses change.
Affected Version(s)
Apache Answer 0 <= 2.0.1