E
xposure of Private Personal Information to an Unauthorized Actor vulnerability in Apache Answer. This issue affects Apache Answer: through 1.7.1. An unauthenticated API endpoint incorrectly exposes full revision history for deleted content. This allows unauthorized user to retrieve restricted or sensitive information. Users are recommended to upgrade to version 2.0.0, which fixes the issue.
References
| Link | Resource |
|---|---|
| https://lists.apache.org/thread/whxloom7mpxlyt5wzdskflsg5mzdzd60 | Mailing List Third Party Advisory |
| http://www.openwall.com/lists/oss-security/2026/02/04/1 | Mailing List Third Party Advisory |
Configurations
History
06 Feb 2026, 14:40
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Apache answer
Apache |
|
| CPE | cpe:2.3:a:apache:answer:*:*:*:*:*:*:*:* | |
| References | () https://lists.apache.org/thread/whxloom7mpxlyt5wzdskflsg5mzdzd60 - Mailing List, Third Party Advisory | |
| References | () http://www.openwall.com/lists/oss-security/2026/02/04/1 - Mailing List, Third Party Advisory |
04 Feb 2026, 19:16
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
04 Feb 2026, 16:16
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.5 |
04 Feb 2026, 11:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-02-04 11:16
Updated : 2026-02-06 14:40
NVD link : CVE-2026-24735
Mitre link : CVE-2026-24735
CVE.ORG link : CVE-2026-24735
JSON object : View
CWE
CWE-359
Exposure of Private Personal Information to an Unauthorized Actor