CVE-2026-24735Disclosure(apache / answer)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Exposure of Private Personal Information to an Unauthorized Actor vulnerability in Apache Answer. This issue affects Apache Answer: through 1.7.1. An unauthenticated API endpoint incorrectly exposes full revision history for deleted content. This allows unauthorized user to retrieve restricted or sensitive information. Users are recommended to upgrade to version 2.0.0, which fixes the issue.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-359

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • answer

Threat summary

  • 6 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 6 classified signals
  • Peaked 2d ago at 2 mentions (2026-02-06); latest day: 1
  • 6 total mentions across 5 days

Affected systems

Vendors
Products
answer

Deep dive

Activity timeline6 mentions / 5d
01122Mentions · 2026-02-04: 1Mentions · 2026-02-05: 1Mentions · 2026-02-06: 2Mentions · 2026-02-08: 1Mentions · 2026-02-09: 1Technical Details · 2026-02-05: 1Technical Details · 2026-02-08: 1Technical Details · 2026-02-09: 102-0402-0502-0602-0802-09
Signal classification1 categories
Disclosure
6100.0%
Referenced assets8 URLs
Classification over time
DateTotalLabels
2026-02-041
Disclosure1
2026-02-051
Disclosure1
2026-02-062
Disclosure2
2026-02-081
Disclosure1
2026-02-091
Disclosure1
Full discourse6 posts
  • Hunter@HunterMapping
    Disclosure

    🚨Alert🚨 CVE-2026-24735 : Apache Answer Flaw Leaks Private Post History 📊 8.5K+ Services are found on the http://hunter.how yearly. 🔗Hunter Link:https://hunter.how/list?searchValue=product.name%3D%22Apache%20Answer%22 👇Query HUNTER : http://product.name="Apache Answer" 📰Refer:https://securityonline.info/cve-2026-24735-apache-answer-flaw-leaks-private-post-history/ https://www.openwall.com/lists/oss-security/2026/02/04/1 #hunterhow #infosec #infosecurity #OSINT #Vulnerability

    Post summary

    The post announces CVE‑2026‑24735, a flaw in Apache Answer that leaks private post history, and lists potentially affected services, but it does not provide technical details, exploit code, or patch information.

    11005493.6K
    25.4K followersView on X
  • Open Source Security mailing list@oss_security
    Disclosure

    CVE-2026-24735: Apache Answer: Revision API Improper Access Control leads to Information Disclosure https://www.openwall.com/lists/oss-security/2026/02/04/1 Severity: important An unauthenticated API endpoint incorrectly exposes full revision history for deleted content

    Post summary

    Apache Answer’s Revision API improperly exposes full revision history for deleted content, causing information disclosure; no PoC, exploit, or patch is mentioned.

    00040759
    4.4K followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-24735 (CVSS:7.5, HIGH) is Analyzed. Exposure of Private Personal Information to an Unauthorized Actor vulnerability in Apache Answer. This issue affects Ap..https://nvd.nist.gov/vuln/detail/CVE-2026-24735 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The post announces CVE‑2026‑24735, giving its CVSS score, severity, and a brief description, but offers no PoC, exploit code, patch, or evidence of active exploitation.

    0000131
    171 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-24735 Exposure of Private Personal Information to an Unauthorized Actor vulnerability in Apache Answer. This issue affects Apache Answer: through 1.7.1. An unauthenticate… https://www.cve.org/CVERecord?id=CVE-2026-24735

    Post summary

    The post announces a new Apache Answer vulnerability (CVE‑2026‑24735) that exposes private personal information to unauthenticated actors, affecting versions up to 1.7.1, with no evidence of exploitation, PoC, patch, or technical details provided.

    00010289
    56.5K followersView on X
  • VulnTracker@vuln_tracker
    Disclosure

    @HunterMapping You now can see the full details about CVE-2026-24735 from https://vulntracker.io/cves/CVE-2026-24735 for FREE

    Post summary

    The tweet announces that full details of CVE-2026-24735 are available for free via a provided link, serving as a disclosure of the vulnerability.

    00000149
    333 followersView on X
  • Karma-X@Karma_X_Inc
    Disclosure

    CVE-2026-24735: Apache Answer Flaw Leaks Private Post History https://securityonline.info/cve-2026-24735-apache-answer-flaw-leaks-private-post-history/

    Post summary

    The article announces the discovery of CVE‑2026‑24735, a flaw in Apache Answer that can leak private post history, with no mention of PoC, exploit, or mitigation.

    0000050
    73 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appapacheanswer---

Explore more