Insufficient Session Expiration in Apache Answer Affects Admin Access
CVE-2026-60053

Currently unrated

Key Information:

Vendor

Apache

Vendor
CVE Published:
5 August 2026

What is CVE-2026-60053?

The insufficient session expiration vulnerability in Apache Answer allows administrative API keys to remain functional even after an administrator's account has been demoted, marked inactive, suspended, or deleted. This flaw grants unauthorized continued access to the API, posing a significant security risk. Users are encouraged to upgrade to version 2.0.2 to patch this issue, ensuring that administrative access is properly revoked when account statuses change.

Affected Version(s)

Apache Answer 0 <= 2.0.1

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

yangxi
.