Description
Improper Authorization vulnerability in Apache Answer.

This issue affects Apache Answer: through 2.0.1.

Any authenticated user can reject arbitrary pending edit-revisions without review permission due to a missing authorization check on the reject operation.
Users are recommended to upgrade to version 2.0.2, which fixes the issue.
Published: 2026-08-05
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an improper authorization flaw that allows any authenticated user to reject arbitrary pending edit revisions in Apache Answer. The missing check on the reject operation means users with basic credentials can remove edit proposals without the required review permission, effectively bypassing the intended content approval workflow. This could lead to tacit removal or loss of user‑generated content and disrupt collaborative editing processes.

Affected Systems

Apache Answer products from the Apache Software Foundation are affected through version 2.0.1. All deployments running any 2.0.1 or earlier release are vulnerable unless they have applied the 2.0.2 patch. No other vendors or versions are reported to be impacted.

Risk and Exploitability

The exploit requires only that the attacker be an authenticated user with access to the application. No additional system privileges or network conditions are needed, and there is no publicly documented attack code. The vulnerability is not listed in the CISA KEV catalog and no EPSS value is available, implying a lower likelihood of widespread exploitation, yet the impact is significant for organizations relying on the edit approval process. Because the flaw is an authorization bypass, it should be considered high risk for settings where unauthorized changes are unacceptable.

Generated by OpenCVE AI on August 5, 2026 at 16:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Apache Answer to version 2.0.2 or later.
  • If an upgrade is not immediately possible, restrict the reject endpoint to users who have explicit review permissions by adjusting role‑based access controls.
  • Review existing user roles to ensure that no unnecessary users possess review rights, and monitor activity logs for suspicious revision rejections.

Generated by OpenCVE AI on August 5, 2026 at 16:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 05 Aug 2026 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Apache
Apache answer
Vendors & Products Apache
Apache answer

Wed, 05 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Description Improper Authorization vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.1. Any authenticated user can reject arbitrary pending edit-revisions without review permission due to a missing authorization check on the reject operation. Users are recommended to upgrade to version 2.0.2, which fixes the issue.
Title Apache Answer: Missing authorization in revision audit reject allows authenticated users to reject pending revisions
Weaknesses CWE-863
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-08-05T16:32:57.029Z

Reserved: 2026-06-06T16:56:13.231Z

Link: CVE-2026-50749

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-05T16:30:12Z

Weaknesses