Apache Answer 2.0.1 External-Login Vulnerability Allows Account Takeover
CVE-2026-48911 Published on August 5, 2026
Apache Answer: Unauthenticated OAuth Email-Binding Account Takeover via Existing User Confirmation Flow
Insufficient Verification of Data Authenticity vulnerability in Apache Answer.
This issue affects Apache Answer: through 2.0.1.
A missing authorization check in the external-login email binding flow allows unauthenticated attackers to take over arbitrary user accounts by tricking victims into clicking a crafted confirmation link.
Users are recommended to upgrade to version 2.0.2, which fixes the issue.
Vulnerability Analysis
CVE-2026-48911 can be exploited with network access, and does not require authorization privileges or user interaction. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have no impact on confidentiality, a high impact on integrity, and no impact on availability.
Weakness Type
Missing Authentication for Critical Function
The software does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
Products Associated with CVE-2026-48911
Want to know whenever a new CVE is published for Apache Answer? stack.watch will email you.
Affected Versions
Apache Software Foundation Apache Answer:- Before and including 2.0.1 is affected.