CVE-2026-25700
Improper Restriction of Security Token Assignment vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. Previously issued administrative tokens were not invalidated after an administrator account was suspended, deleted, or deactivated, allowing continued access to administrative APIs until the token expired. Users are recommended to upgrade to version 2.0.1, which fixes the issue.
Scoring
- Severity
- HIGH
- CVSS base score
- 7.2
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
- EPSS probability
- 0.45%
- CWE
- CWE-1259
- Published
- 2026-06-10
- Last modified
- 2026-06-20
Affected products
- Apache Software Foundation Apache Answer
Weakness type
Related vulnerabilities
- CVE-2026-58429 — Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints
- CVE-2026-54593 — Pterodactyl's improper JWT scoping allows subuser to upload files when not explicitly granted `file.create` permissions
- CVE-2026-40264 — OpenBao's Token Store Allows Cross-Namespace Renewal, Revocation
- CVE-2024-45448 — Page table protection configuration vulnerability in the trusted firmware module...
- CVE-2024-41948 — biscuit-java vulnerable to public key confusion in third party block
- CVE-2024-36111 — KubePi's JWT token validation has a defect
- CVE-2022-23541 — jsonwebtoken's insecure implementation of key retrieval function could lead to Forgeable Public/Private Tokens from RSA to HMAC
- CVE-2022-23551 — AAD Pod Identity obtaining token with backslash