CVE-2026-24072

EUVD-2026-26944
An escalation of privilege bug in various modules in Apache HTTP 2.4.66 and earlier allows local .htaccess authors to read files with the privileges of the httpd user.

Users are recommended to upgrade to version 2.4.67, which fixes this issue.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
8.8 HIGH
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 17%
Affected Products (NVD)
VendorProductVersion
apachehttp_server
𝑥
< 2.4.67
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
apache2
bookworm
vulnerable
bookworm (security)
2.4.67-1~deb12u2
fixed
bullseye
vulnerable
bullseye (security)
2.4.67-1~deb11u1
fixed
forky
vulnerable
sid
2.4.67-1
fixed
trixie
vulnerable
trixie (security)
2.4.67-1~deb13u2
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
apache2
bionic
needs-triage
focal
needs-triage
jammy
Fixed 2.4.52-1ubuntu4.20
released
noble
Fixed 2.4.58-1ubuntu8.12
released
questing
Fixed 2.4.64-1ubuntu3.4
released
resolute
Fixed 2.4.66-2ubuntu2.1
released
trusty
needs-triage
xenial
needs-triage