CVE-2026-24072

Security update for apache2

Description

A flaw was found in Apache HTTP Server. This escalation of privilege vulnerability allows local attackers, specifically those with the ability to author .htaccess files, to read sensitive files. This flaw enables unauthorized access to files with the privileges of the httpd user, potentially leading to information disclosure.

Metrics

Severity
high
no public PoC known
8.8
Source: nvd-v3
49.3 %
High — this CVE ranks above the median of all CVEs scored today (rank ≥ 36%).
0.7 %
Low — model estimates < 1% exploitation likelihood.
Published
2026-08-27 14:44 UTC
CWE-269

Weakness classes (CWE)

  • CWE-269Class

    Improper Privilege Management

    The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

    cwe.mitre.org →

Affected products

Products and version ranges extracted from the vendor/CERT advisory. A range like „<4.14.6“ implies the update recommendation „upgrade to 4.14.6 or later“.

  • apache

    http_server2.4.67

  • bitnami

    apache2.4.0

  • bitnami

    apache2.4.30

  • bitnami

    apache2.4.66

  • bitnami

    apache

References & sources

Linked CVEs

Linked advisories

IDCVE-2026-24072