Severity: moderate 

Affected versions:

- Apache HTTP Server through 2.4.66

Description:

An escalation of privilege bug in various modules in Apache HTTP 2.4.66 and 
earlier allows local .htaccess authors to read files with the privileges of the 
httpd user.

Users are recommended to upgrade to version 2.4.67, which fixes this issue.

Credit:

y7syeu (finder)

References:

https://httpd.apache.org/security/vulnerabilities_24.html
https://httpd.apache.org/
https://www.cve.org/CVERecord?id=CVE-2026-24072

Timeline:

2026-01-20: Report received
2026-05-04: fixed in 2.4.x by r1933350

Reply via email to