CVE-2026-24072

An escalation of privilege bug in various modules in Apache HTTP 2.4.66 and earlier allows local .htaccess authors to read files with the privileges of the httpd user. Users are recommended to upgrade to version 2.4.67, which fixes this issue.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:apache:http_server:*:*:*:*:*:*:*:*

History

04 May 2026, 20:27

Type Values Removed Values Added
First Time Apache http Server
Apache
CPE cpe:2.3:a:apache:http_server:*:*:*:*:*:*:*:*
References () https://httpd.apache.org/security/vulnerabilities_24.html - () https://httpd.apache.org/security/vulnerabilities_24.html - Vendor Advisory
References () http://www.openwall.com/lists/oss-security/2026/05/04/18 - () http://www.openwall.com/lists/oss-security/2026/05/04/18 - Mailing List, Third Party Advisory

04 May 2026, 19:16

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.8

04 May 2026, 18:16

Type Values Removed Values Added
References
  • () http://www.openwall.com/lists/oss-security/2026/05/04/18 -

04 May 2026, 13:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-04 13:16

Updated : 2026-05-04 20:27


NVD link : CVE-2026-24072

Mitre link : CVE-2026-24072

CVE.ORG link : CVE-2026-24072


JSON object : View

Products Affected

apache

  • http_server
CWE
CWE-269

Improper Privilege Management