CVE-2026-25700High· 7.2▾ TwilightApache Answer: AdminToken not invalidated after admin deactivation
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 39.6 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Aug 18.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
0.4%
Improper Restriction of Security Token Assignment vulnerability in Apache Answer.
This issue affects Apache Answer: through 2.0.0.
Previously issued administrative tokens were not invalidated after an administrator account was suspended, deleted, or deactivated, allowing continued access to administrative APIs until the token expired. Users are recommended to upgrade to version 2.0.1, which fixes the issue.
github.com/apache/incubator-answer < 2.0.1github.com/apache/answer < 2.0.1Upgrade to a patched release:
github.com/apache/incubator-answer 2.0.1github.com/apache/answer 2.0.1Connected by shared product, vendor, weakness, or advisory.
CVE-2026-34031Medium· 6.5Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability
CVE-2026-33582Medium· 6.5Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability
CVE-2026-34905Medium· 6.5Apache Answer has an Exposure of Sensitive Information to an Unauthorized Actor vulnerability
CVE-2026-34033Medium· 5.4Apache Answer vulnerable to Cross-site Scripting
CVE-2026-25699Medium· 6.1Apache Answer has an Exposure of Private Personal Information to an Unauthorized Actor vulnerability
CVE-2026-25688Medium· 6.1Apache Answer has an Improper Neutralization of Alternate XSS Syntax vulnerability