PT-2026-68193 · Apache · Apache Answer
CVSS v3.1
9.1
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Apache Answer versions prior to 2.0.2
Description
Insufficient Session Expiration allows administrative API keys to remain active even after the associated administrator account is demoted, marked as inactive, suspended, or deleted. This results in unauthorized continued access to administrative functions until the keys are manually removed.
Recommendations
Upgrade to version 2.0.2.
Exploit
Fix
Insufficient Session Expiration
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apache Answer