
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-24735 is an information disclosure vulnerability in Apache Answer, classified as "Exposure of Private Personal Information to an Unauthorized Actor" (CWE-359). An unauthenticated API endpoint incorrectly exposes the full revision history for deleted content, allowing unauthorized users to retrieve restricted or sensitive information. The vulnerability affects Apache Answer through version 1.7.1, and was publicly disclosed on February 4, 2026, with a fix available in version 2.0.0. It carries a CVSS v3.1 base score of 7.5 (High) (Apache Mailing List, oss-security).
The root cause is improper access control on the Revision API endpoint (CWE-359), which fails to enforce authentication or authorization checks before returning revision history data. Specifically, the API endpoint exposes the full edit/revision history of content that has been deleted by users or administrators, meaning data intended to be removed remains accessible. An attacker can exploit this by sending unauthenticated HTTP requests directly to the revision history API endpoint, requiring no credentials, special privileges, or user interaction. The vulnerability was reported by Sho Odagiri of GMO Cybersecurity by Ierae, Inc. (oss-security, Apache Mailing List).
Successful exploitation allows any unauthenticated remote attacker to retrieve the full revision history of deleted posts, answers, or questions from an Apache Answer instance. This may expose sensitive or confidential information that users or administrators believed had been permanently removed, including potentially personal data, internal discussions, or proprietary content. There is no integrity or availability impact; the risk is confined to confidentiality, but the exposure of deleted content could have significant privacy and compliance implications for organizations using Apache Answer as a knowledge-sharing platform (Apache Mailing List, oss-security).
/api/v1/revisions or similar, based on the application's API structure)./revisions or /revision) from external or unexpected IP addresses.The Apache Software Foundation has released version 2.0.0 of Apache Answer, which fixes this vulnerability by enforcing proper access controls on the revision history API endpoint. All users running Apache Answer through version 1.7.1 are strongly recommended to upgrade to version 2.0.0 immediately. No configuration-based workaround has been officially documented; upgrading is the only confirmed remediation (oss-security, Apache Mailing List).
The vulnerability was discussed on the oss-security mailing list and received coverage from security news outlets including SecurityOnline.info and TheHackerWire. Social media posts on Bluesky and Mastodon noted the disclosure. Community reaction was moderate, with the primary concern being the ease of exploitation due to the lack of authentication requirements, though the limited deployment footprint of Apache Answer tempered broader alarm (oss-security, SecurityOnline).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."