{
  "affected": [
    {
      "ranges": [
        {
          "database_specific": {
            "cpe": "cpe:2.3:a:apache:answer:*:*:*:*:*:*:*:*",
            "extracted_events": [
              {
                "introduced": "0"
              },
              {
                "fixed": "2.0.2"
              }
            ],
            "source": "CPE_RANGE"
          },
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "3b9f1370612e690a0b7f230f05e688930db4c6d3"
            }
          ],
          "repo": "https://github.com/apache/answer",
          "type": "GIT"
        }
      ]
    }
  ],
  "database_specific": {
    "cna_assigner": "apache",
    "cwe_ids": [
      "CWE-613"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/60xxx/CVE-2026-60053.json",
    "unresolved_ranges": [
      {
        "extracted_events": [
          {
            "last_affected": "2.0.1"
          }
        ],
        "source": "AFFECTED_FIELD"
      },
      {
        "extracted_events": [
          {
            "fixed": "2.0.1"
          }
        ],
        "source": "DESCRIPTION"
      }
    ]
  },
  "details": "Insufficient Session Expiration vulnerability in Apache Answer.\n\nThis issue affects Apache Answer: through 2.0.1.\n\nAdministrative API keys remained usable after the owning administrator was demoted or the account was marked inactive, suspended, or deleted, allowing continued access until the keys were explicitly removed.\nUsers are recommended to upgrade to version 2.0.2, which fixes the issue.",
  "id": "CVE-2026-60053",
  "modified": "2026-08-12T03:51:27.233431065Z",
  "published": "2026-08-05T15:13:10.355Z",
  "references": [
    {
      "type": "WEB",
      "url": "http://www.openwall.com/lists/oss-security/2026/08/05/14"
    },
    {
      "type": "ADVISORY",
      "url": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/60xxx/CVE-2026-60053.json"
    },
    {
      "type": "ADVISORY",
      "url": "https://lists.apache.org/thread/2vkcj3bdvso6cywnklt2vtkc2m4o0b5c"
    },
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-60053"
    }
  ],
  "schema_version": "1.9.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
      "type": "CVSS_V3"
    }
  ],
  "summary": "Apache Answer: Residual Administrative API Key Access After Role or Account Revocation"
}