CVE-2026-24072
Security update for apache2
Description
A flaw was found in Apache HTTP Server. This escalation of privilege vulnerability allows local attackers, specifically those with the ability to author .htaccess files, to read sensitive files. This flaw enables unauthorized access to files with the privileges of the httpd user, potentially leading to information disclosure.
Metrics
Weakness classes (CWE)
CWE-269Class
Improper Privilege Management
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
cwe.mitre.org →
Affected products
Products and version ranges extracted from the vendor/CERT advisory. A range like „<4.14.6“ implies the update recommendation „upgrade to 4.14.6 or later“.
apache
http_server2.4.67
bitnami
apache2.4.0
bitnami
apache2.4.30
bitnami
apache2.4.66
bitnami
apache
References & sources
- https://httpd.apache.org/security/vulnerabilities_24.htmleuvd
- http://www.openwall.com/lists/oss-security/2026/05/05/6
- https://nvd.nist.gov/vuln/detail/CVE-2026-29168web
- http://www.openwall.com/lists/oss-security/2026/05/04/20
- http://www.openwall.com/lists/oss-security/2026/05/05/12
- https://nvd.nist.gov/vuln/detail/CVE-2026-29169web
- http://www.openwall.com/lists/oss-security/2026/05/04/18
- https://nvd.nist.gov/vuln/detail/CVE-2026-24072web
- http://www.openwall.com/lists/oss-security/2026/05/05/9web
- https://nvd.nist.gov/vuln/detail/CVE-2026-28780web
- https://access.redhat.com/errata/RHSA-2026:21391web
- https://access.redhat.com/errata/RHSA-2026:21433web
- https://access.redhat.com/errata/RHSA-2026:22140web
- https://access.redhat.com/errata/RHSA-2026:27200web
- https://access.redhat.com/errata/RHSA-2026:27201web
- https://access.redhat.com/security/cve/CVE-2026-28780web
- https://bugzilla.redhat.com/show_bug.cgi?id=2466913web
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-28780.jsonweb
- https://access.redhat.com/errata/RHSA-2026:36373web
- https://access.redhat.com/errata/RHSA-2026:36831web
Linked CVEs
- CVE-2026-34059
Buffer Over-read vulnerability in Apache HTTP Server.
highCVSSv3 7.5 - CVE-2026-34032
Improper Null Termination, Out-of-bounds Read vulnerability in Apache HTTP Server.
mediumCVSSv3 5.3 - CVE-2026-33857
Out-of-bounds Read vulnerability in mod_proxy_ajp of Apache HTTP Server.
mediumCVSSv3 5.3 - CVE-2026-33523
HTTP response splitting vulnerability in multiple Apache HTTP Server modules with untrusted or compromised backend servers.
mediumCVSSv3 6.5 - CVE-2026-33007
A NULL pointer dereference in the mod_authn_socache in Apache HTTP Server 2.4.66 and earlier allows an unauthenticated remote user to cra…
mediumCVSSv3 5.3 - CVE-2026-33006
A timing attack against mod_auth_digest in Apache HTTP Server 2.4.66 allows a bypass of Digest authentication by a remote attacker.
mediumCVSSv3 4.8 - CVE-2026-29169
A NULL pointer dereference in mod_dav_lock in Apache HTTP Server 2.4.66 and earlier may allow an attacker to crash the server with a mali…
highCVSSv3 7.5 - CVE-2026-29168
Allocation of Resources Without Limits or Throttling vulnerability in Apache HTTP Server's mod_md via OCSP response data.
highCVSSv3 7.3 - CVE-2026-28780
Heap-based Buffer Overflow vulnerability in mod_proxy_ajp of Apache HTTP Server.
criticalCVSSv3 9.8 - CVE-2026-23918
Double Free and possible RCE vulnerability in Apache HTTP Server with the HTTP/2 protocol.
highCVSSv3 8.8