What is CVE-2026-60053?
CVE-2026-60053 is an insufficient session expiration vulnerability in Apache Answer up to version 2.0.1. Administrative API keys remain usable even after the owning admin account is demoted, deactivated, suspended, or deleted, potentially allowing unauthorized access. Users are urged to update to the latest version immediately.
Azərbaycanca: CVE-2026-60053, Apache Answer-in 2.0.1-ə qədər olan versiyalarında aşkarlanan zəif sessiya müddəti zəifliyidir. Administrator rütbəsi endiriləndə, hesab qeyri-aktiv, suspend ediləndə və ya silinəndə belə API açarları aktiv qalır, bu da icazəsiz girişə səbəb ola bilər. İstifadəçilərə dərhal ən son versiyaya yeniləmə tövsiyə edilir.
Related CVEs
link basis: shared vendor: Apache
FAQ2
Which versions of Apache Answer are affected by CVE-2026-60053?
This vulnerability affects Apache Answer up to version 2.0.1.
What risk arises with API keys after an admin account is deactivated in CVE-2026-60053?
API keys remain usable even after the owning admin account is demoted, deactivated, suspended, or deleted, potentially allowing unauthorized access.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.