What is CVE-2026-50749?
CVE-2026-50749 is an improper authorization vulnerability in Apache Answer that affects versions through 2.0.1. It allows any authenticated user to reject pending edit revisions without the required review permission due to a missing authorization check on the reject operation. Users are recommended to upgrade to the latest version immediately.
Azərbaycanca: CVE-2026-50749 Apache Answer platformasında aşkarlanmış düzgün olmayan avtorizasiya zəifliyidir. Bu zəiflik 2.0.1 versiyasına qədər təsir edir və autentifikasiya olunmuş istənilən istifadəçiyə xüsusi icazə (review permission) tələb olunmadan gözləyən redaktə rəylərini rədd etməyə imkan verir. İstifadəçilərə dərhal ən son versiyaya yüksəlmələri tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-862; shared vendor: Apache
FAQ2
Does an attacker need to be authenticated to exploit CVE-2026-50749?
Yes, any authenticated user can exploit this vulnerability.
What is the most effective mitigation for CVE-2026-50749?
The most effective mitigation is to upgrade to the latest version immediately.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.