oss-sec mailing list archives
CVE-2026-60053: Apache Answer: Residual Administrative API Key Access After Role or Account Revocation
From: Enxin Xie <linkinstar () apache org>
Date: Wed, 05 Aug 2026 14:27:26 +0000
Severity: low Affected versions: - Apache Answer through 2.0.1 Description: Insufficient Session Expiration vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.1. Administrative API keys remained usable after the owning administrator was demoted or the account was marked inactive, suspended, or deleted, allowing continued access until the keys were explicitly removed. Users are recommended to upgrade to version 2.0.2, which fixes the issue. Credit: yangxi (reporter) References: https://answer.apache.org https://www.cve.org/CVERecord?id=CVE-2026-60053
Current thread:
- CVE-2026-60053: Apache Answer: Residual Administrative API Key Access After Role or Account Revocation Enxin Xie (Aug 05)
