Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.1

CVE-2026-60053: Apache Answer: Unsecured API Keys After Admin Role Change

CVE-2026-60053 · published 1 month ago
Summary

Apache Answer versions through 2.0.1 allow former administrators to retain access to sensitive keys. This is a security risk because it could let someone who no longer has permission access important data. To fix this, upgrade to version 2.0.2 or later.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
apache software foundation apache answer <= 2.0.1
Original advisory text
Insufficient Session Expiration vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.1. Administrative API keys remained usable after the owning administrator was demoted...
Insufficient Session Expiration vulnerability in Apache Answer.

This issue affects Apache Answer: through 2.0.1.

Administrative API keys remained usable after the owning administrator was demoted or the account was marked inactive, suspended, or deleted, allowing continued access until the keys were explicitly removed.
Users are recommended to upgrade to version 2.0.2, which fixes the issue.
Severity
9.1 Critical
Exploitation
EPSS <1%
Type
CWE-613Insufficient Session Expiration
Timeline
Published5 Aug 2026
Updated27 Sep 2026
First seen5 Aug 2026
Sources
CVE-2026-60053 · MITRE
Track software like this
Free during beta