Junglewise Threat Intelligence

CVE-2026-34905: Apache Answer information disclosure in unlisted questions feature

CVE-2026-34905 · Severity: medium · CVSS 6.5 · Published 2026-06-09

Technologies: github.com/apache/answer (Go), Apache Software Foundation Answer, github.com/apache/incubator-answer (Go). Vendors: Go, Apache Software Foundation, Apache.

Executive brief

Apache Answer, a community-driven Q&A platform, contains a security flaw where 'unlisted' questions are not properly protected. Any logged-in user can bypass intended visibility restrictions to view private questions, their answers, comments, and edit history. This could lead to the unauthorized disclosure of sensitive internal discussions or private information.

Technical details

An information disclosure vulnerability exists in Apache Answer's 'unlisted question' feature due to missing authorization checks on direct API endpoints. While these questions are hidden from the standard web UI, the underlying API does not validate if the requesting authenticated user has the permission to view unlisted content. An attacker with a valid account can query these endpoints to retrieve unlisted questions, answers, comments, and revision history. The issue is resolved in version 2.0.1 by enhancing visibility checks in the answer and comment services to include administrator and moderator validation.

Affected products

  • Apache Answer through 2.0.0

Timeline

  • 2026-05-09: patched: Fix committed to repository
  • 2026-06-09: disclosed: Public advisory released

References

Related threats