CVE-2026-50749 PUBLISHED

Apache Answer: Missing authorization in revision audit reject allows authenticated users to reject pending revisions

Assigner: apache
Reserved: 06.06.2026 Published: 05.08.2026 Updated: 05.08.2026

Improper Authorization vulnerability in Apache Answer.

This issue affects Apache Answer: through 2.0.1.

Any authenticated user can reject arbitrary pending edit-revisions without review permission due to a missing authorization check on the reject operation. Users are recommended to upgrade to version 2.0.2, which fixes the issue.

Product Status

Vendor Apache Software Foundation
Product Apache Answer
Versions Default: unaffected
  • affected from 0 to 2.0.1 (incl.)

Credits

  • tonghuaroot reporter
  • Mattia Campanelli reporter
  • Cavan Loughran reporter
  • Xi Yang reporter

References

Problem Types

  • CWE-863 Incorrect Authorization CWE