---
id: CVE-2026-25699
aliases:
  - GHSA-w754-5646-xq9j
title: >-
  Apache Answer has an Exposure of Private Personal Information to an
  Unauthorized Actor vulnerability
summary: >-
  Apache Answer has an Exposure of Private Personal Information to an
  Unauthorized Actor vulnerability
severity: medium
cvss: 6.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'
vendor: apache
product: github.com/apache/incubator-answer
ecosystem: go
affected:
  - github.com/apache/incubator-answer < 1.7.2-0.20260206073245-92994b49976b
patched:
  - github.com/apache/incubator-answer 1.7.2-0.20260206073245-92994b49976b
published: '2026-06-09'
updated: '2026-07-30'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/GHSA-w754-5646-xq9j'
references:
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-25699'
  - url: >-
      https://github.com/apache/answer/commit/92994b49976b6206a7000d045d924ec4fd5be1be
  - url: 'https://github.com/apache/answer'
  - url: 'https://github.com/apache/answer/releases/tag/v2.0.1'
  - url: 'https://lists.apache.org/thread/c36k4hzwhncqo0qfn5fg57f1gkjhyfv8'
  - url: 'http://www.openwall.com/lists/oss-security/2026/06/09/6'
tags:
  - osv
  - go
epss: 0.00406
epssPercentile: 0.347
ingestedAt: '2026-07-30T19:09:51.903Z'
---

## Overview

Exposure of Private Personal Information to an Unauthorized Actor vulnerability in Apache Answer.

This issue affects Apache Answer: through 2.0.0.

Timeline-related APIs lacked proper authorization checks, allowing regular authenticated users to access deleted, private, or unapproved content and its revision history.
Users are recommended to upgrade to version 2.0.1, which fixes the issue.

## Affected packages

- `github.com/apache/incubator-answer < 1.7.2-0.20260206073245-92994b49976b`

## Remediation

Upgrade to a patched release:

- `github.com/apache/incubator-answer 1.7.2-0.20260206073245-92994b49976b`
