What is CVE-2026-60023?
This vulnerability in Apache Answer allows unauthorized users to retrieve deleted or pending answers via the single-answer read path when the parent question remains visible. It exposes sensitive information that should be restricted. Users should immediately upgrade from versions through 2.0.1 to the latest patched release.
Azərbaycanca: Bu zəiflik Apache Answer platformasında silinmiş və ya gözləmədə olan cavabların icazəsiz istifadəçilərə açıqlanmasına səbəb olur. Əsas sual görünən qaldıqda, tək-cavab oxuma yolu ilə məxfi məlumatlar əldə edilə bilər. İstifadəçilərə dərhal 2.0.1 və daha əvvəlki versiyalardan ən son təhlükəsizlik yeniləməsinə keçmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-200; shared vendor: Apache
FAQ2
What type of confidential data is exposed by CVE-2026-60023 in the Apache Answer platform?
This vulnerability leads to the unauthorized disclosure of deleted or pending answers.
To mitigate CVE-2026-60023, what version should users upgrade to?
Users are advised to upgrade from versions through 2.0.1 to the latest patched release.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.