Medium severity6.1NVD Advisory· Published Jun 9, 2026· Updated Jun 10, 2026
CVE-2026-25699
CVE-2026-25699
Description
Exposure of Private Personal Information to an Unauthorized Actor vulnerability in Apache Answer.
This issue affects Apache Answer: through 2.0.0.
Timeline-related APIs lacked proper authorization checks, allowing regular authenticated users to access deleted, private, or unapproved content and its revision history. Users are recommended to upgrade to version 2.0.1, which fixes the issue.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2Patches
Vulnerability mechanics
References
2- www.openwall.com/lists/oss-security/2026/06/09/6nvdMailing ListThird Party Advisory
- lists.apache.org/thread/c36k4hzwhncqo0qfn5fg57f1gkjhyfv8nvdMailing ListVendor Advisory
News mentions
1- Apache HTTP Server and Answer: 22 Vulnerabilities Disclosed, Including Critical FlawsVypr Intelligence · Jun 10, 2026