216.73.216.6

CVE-2026-25700

· Published 10/06/2026 16:16 · Modified 10/06/2026 18:35

Labels: CVE-2026-25700 2026-06-10CVE-2026-25700CWE-1259[email protected]

Essential information

Published
10/06/2026 16:16
Modified
10/06/2026 18:35
Author
Creator
CVSS
7.2 HIGH (v3.1)
CISA KEV
No
CWE
CWE-1259
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

CVSS metrics

Description

Improper Restriction of Security Token Assignment vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. Previously issued administrative tokens were not invalidated after an administrator account was suspended, deleted, or deactivated, allowing continued access to administrative APIs until the token expired. Users are recommended to upgrade to version 2.0.1, which fixes the issue.

NVD status

Status
Modified — CVE has been recently published to the CVE List and has been received by the NVD.
Source
nist-nvd-api
NVD
View on NVD

Affected products (CPE)

ProductCPE
apache / answer cpe:2.3:a:apache:answer:*:*:*:*:*:*:*:*

References