CVE-2026-24072

medium Apache
Published: May 4, 2026 (9 days ago)
Last Modified: May 5, 2026
Vendor: Apache
Source: MITRE

Description

An escalation of privilege bug in various modules in Apache HTTP 2.4.66 and earlier allows local .htaccess authors to read files with the privileges of the httpd user. Users are recommended to upgrade to version 2.4.67, which fixes this issue.

CWE

CWE-269

Affected Products

Apache Software Foundation Apache HTTP Server

References