Security Advisory

CVE-2026-48912

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-08-05 15:10:08
Last updated 2026-08-06 14:37:55
Assigner apache
CVSS score not scored
State PUBLISHED

Description

Improper Input Validation vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.1. A missing ownership check in the avatar-cleanup logic allows any authenticated user to delete other users' uploaded files by supplying their file URLs. Users are recommended to upgrade to version 2.0.2, which fixes the issue.