What is CVE-2026-48911?
An insufficient verification of data authenticity flaw in Apache Answer's external-login email binding flow (CVE-2026-48911) allows unauthenticated attackers to hijack arbitrary user accounts through phishing-like techniques. Affects versions up to 2.0.1; immediate update to the latest patched version is recommended.
Azərbaycanca: Apache Answer platformasında email bağlama axınında çatışmayan avtorizasiya yoxlaması zəifliyi (CVE-2026-48911) aşkar edilib. Bu, autentifikasiya olunmamış hücumçulara istifadəçiləri aldadaraq onların hesablarını ələ keçirməyə imkan yaradır. Apache Answer-in 2.0.1 versiyasına qədər təsir göstərir; dərhal son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-287; shared vendor: Apache
FAQ2
How can I protect myself from CVE-2026-48911?
You must immediately update the affected Apache Answer platform to the latest patched version beyond 2.0.1.
Who is affected by CVE-2026-48911?
All users running Apache Answer up to version 2.0.1 are affected, as the flaw can be exploited by unauthenticated attackers.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.