A AegiFlow
HIGHCVSS 7.2EPSS 0.4%

CVE-2026-25700

Apache Answer: AdminToken not invalidated after admin deactivation

Published
2026-06-10
Modified
2026-08-17
EPSS percentile
37%
Aliases
GHSA-4gw2-vg4x-7p29
Sources
github-advisory

Summary

Improper Restriction of Security Token Assignment vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. Previously issued administrative tokens were not invalidated after an administrator account was suspended, deleted, or deactivated, allowing continued access to administrative APIs until the token expired. Users are recommended to upgrade to version 2.0.1, which fixes the issue.

Affected packages

EcosystemPackageAffected versionsFixed versions
Gogithub.com/apache/answer2.0.1
Gogithub.com/apache/incubator-answer2.0.1

Remediation: Upgrade to 2.0.1 or later.

References

Includes data from the GitHub Advisory Database, licensed under CC-BY 4.0.

CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.

EPSS scores provided by the FIRST.org Exploit Prediction Scoring System.