CVE-2026-48912

Improper Input Validation vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.1. A missing ownership check in the avatar-cleanup logic allows any authenticated user to delete other users' uploaded files by supplying their file URLs. Users are recommended to upgrade to version 2.0.2, which fixes the issue.
References
Link Resource
https://lists.apache.org/thread/b9jnttmspd9kp4vgbvb32dcqb4201flq Mailing List Vendor Advisory
http://www.openwall.com/lists/oss-security/2026/08/05/11 Mailing List Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:apache:answer:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-08-05 16:16

Updated : 2026-08-06 18:38


NVD link : CVE-2026-48912

Mitre link : CVE-2026-48912

CVE.ORG link : CVE-2026-48912


JSON object : View

Products Affected

apache

  • answer
CWE
CWE-639

Authorization Bypass Through User-Controlled Key