CVE-2026-60053
Received Received - Intake

Insufficient Session Expiration in Apache Answer

Vulnerability report for CVE-2026-60053, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-05

Last updated on: 2026-08-05

Assigner: Apache Software Foundation

Description

Insufficient Session Expiration vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.1. Administrative API keys remained usable after the owning administrator was demoted or the account was marked inactive, suspended, or deleted, allowing continued access until the keys were explicitly removed. Users are recommended to upgrade to version 2.0.2, which fixes the issue.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-05
Last Modified
2026-08-05
Generated
2026-08-05
AI Q&A
2026-08-05
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
apache answer to 2.0.1 (inc)
apache answer 2.0.2

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-613 According to WASC, "Insufficient Session Expiration is when a web site permits an attacker to reuse old session credentials or session IDs for authorization."

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in Apache Answer is an Insufficient Session Expiration issue. Administrative API keys remained active even after the owning administrator was demoted, account was marked inactive, suspended, or deleted. This allowed continued unauthorized access until keys were manually removed.

Detection Guidance

Check for active administrative API keys in Apache Answer versions before 2.0.2. Review user roles and account statuses to identify demoted, inactive, suspended, or deleted accounts with retained API keys.

Impact Analysis

If you use Apache Answer versions through 2.0.1, attackers could exploit this to maintain access to administrative functions even after your account is deactivated or privileges are revoked. This could lead to unauthorized data access, modifications, or system control.

Compliance Impact

This vulnerability could violate compliance requirements that mandate timely revocation of access upon role changes or account deactivation, such as GDPR's data protection principles or HIPAA's access control rules. Unauthorized continued access risks non-compliance.

Mitigation Strategies

Upgrade Apache Answer to version 2.0.2 or later to fix the issue. Review and revoke all administrative API keys associated with demoted, inactive, suspended, or deleted accounts.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-60053. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart