Apache · Apache Answer · CVE-2026-60053
**Name of the Vulnerable Software and Affected Versions**
Apache Answer versions prior to 2.0.2
**Description**
Insufficient Session Expiration allows administrative API keys to remain active even after the associated administrator account is demoted, marked as inactive, suspended, or deleted. This results in unauthorized continued access to administrative functions until the keys are manually removed.
**Recommendations**
Upgrade to version 2.0.2.