CVE-2026-24072

high
Published 2026-05-04 · Modified 2026-05-04
CVSS v3
8.8
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS v2
VIR risk
8.8

Description

An escalation of privilege bug in various modules in Apache HTTP 2.4.66 and earlier allows local .htaccess authors to read files with the privileges of the httpd user. Users are recommended to upgrade to version 2.4.67, which fixes this issue.

Predictions

Exploit likelihood
92%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: suse — https://www.suse.com/security/cve/CVE-2026-24072.html

vendor Authored 2026-05-27

Vendor advisory: security@apache.org — https://httpd.apache.org/security/vulnerabilities_24.html

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2026-24072

OS impact

OSVersionStatusFixed in
debian debianbookwormfixed2.4.67-1~deb12u2
debian debianbullseyefixed2.4.67-1~deb11u1
debian debianforkyfixed2.4.67-1
debian debiansidfixed2.4.67-1
debian debiantrixiefixed2.4.67-1~deb13u2
suse slesaffected

Application impact

VendorProductVersionsFixed
apache apachehttp_server{"endExcluding":"2.4.67"}2.4.67

References

CWEs

CWE-269

Verify integrity in audit chain (admin only). AS-IS.