Back to CVE List

CVE-2026-24072

HIGH SEVERITY

CVSS Score & Metrics

Base Score
8.8 / 10
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Vulnerability Description

An escalation of privilege bug in various modules in Apache HTTP 2.4.66 and earlier allows local .htaccess authors to read files with the privileges of the httpd user.

Users are recommended to upgrade to version 2.4.67, which fixes this issue.

Vulnerability Details

Published Date
Last Modified
CWE ID
CWE-269
Source
NVD
Vendor
Apache Software Foundation
Product
Apache HTTP Server

External References

Discussion (0)

Add Comment

No comments yet. Be the first!