CVE-2026-48912
Last modified
CVE-2026-48912 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. Improper Input Validation vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.1. A missing ownership check in the avatar-cleanup logic allows any authenticated user to delete other users' uploaded files by supplying their file URLs. Users are recommended to upgrade to version 2.0.2, which fixes the issue.. EPSS estimates a 0.18% chance of exploitation in the next 30 days.
Description
Improper Input Validation vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.1. A missing ownership check in the avatar-cleanup logic allows any authenticated user to delete other users' uploaded files by supplying their file URLs. Users are recommended to upgrade to version 2.0.2, which fixes the issue.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Apache | Answer | < 2.0.2 |
References
- https://lists.apache.org/thread/b9jnttmspd9kp4vgbvb32dcqb4201flqMailing List, Vendor Advisory
- http://www.openwall.com/lists/oss-security/2026/08/05/11Mailing List, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-48912?
How severe is CVE-2026-48912?
How do I fix CVE-2026-48912?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-48907A vulnerability in the JCE editor extension for Joomla allow…9.8
- CVE-2026-48908A vulnerability in SP Page Builder for Joomla allows unauthe…9.8
- CVE-2026-48909SP LMS (com_splms) < 4.1.4 by JoomShaper deserializes user-c…9.5
- CVE-2026-4891A heap-based out-of-bounds read vulnerability in the DNSSEC …5.3
- CVE-2026-48910A carefully crafted editing request could trigger an XSS vul…6.5
- CVE-2026-48911Insufficient Verification of Data Authenticity vulnerability…7.5
- CVE-2026-48913Use After Free vulnerability in Apache HTTP Server module mo…7.3
- CVE-2026-48914A flaw was found in QEMU's virtio-blk device. The issue aris…6.7
- CVE-2026-48916Jenkins LDAP Plugin 807.v7d7de30930cf and earlier follows LD…6.6
- CVE-2026-48917Jenkins LDAP Plugin 807.v7d7de30930cf and earlier deserializ…6.6
- CVE-2026-48918Jenkins Active Directory Plugin 2.41 and earlier follows LDA…6.6
- CVE-2026-48919Jenkins Active Directory Plugin 2.41 and earlier deserialize…6.6
Are you affected by CVE-2026-48912?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
