BIT-apache-2026-24072

See a problem?
Import Source
https://github.com/bitnami/vulndb/tree/main/data/apache/BIT-apache-2026-24072.json
JSON Data
https://api.osv.dev/v1/vulns/BIT-apache-2026-24072
Aliases
  • CVE-2026-24072
Published
2026-05-05T08:38:59.092Z
Modified
2026-05-05T09:30:23.146625Z
Summary
Apache HTTP Server: mod_rewrite elevation of privileges via ap_expr
Details

An escalation of privilege bug in various modules in Apache HTTP 2.4.66 and earlier allows local .htaccess authors to read files with the privileges of the httpd user.

Users are recommended to upgrade to version 2.4.67, which fixes this issue.

Database specific
{
    "cpes": [
        "cpe:2.3:a:apache:http_server:*:*:*:*:*:*:*:*"
    ],
    "severity": "High"
}
References

Affected packages

Bitnami / apache

Package

Name
apache
Purl
pkg:bitnami/apache

Severity

  • 8.8 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator

Affected ranges

Type
SEMVER
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.4.67

Database specific

source
"https://github.com/bitnami/vulndb/tree/main/data/apache/BIT-apache-2026-24072.json"