CVE-2026-24072
high
CVSS v3
8.8
CVSS v2
—
VIR risk
8.8
Description
An escalation of privilege bug in various modules in Apache HTTP 2.4.66 and earlier allows local .htaccess authors to read files with the privileges of the httpd user. Users are recommended to upgrade to version 2.4.67, which fixes this issue.
Predictions
Exploit likelihood
92%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: suse — https://www.suse.com/security/cve/CVE-2026-24072.html
Vendor advisory: security@apache.org — https://httpd.apache.org/security/vulnerabilities_24.html
Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2026-24072
OS impact
| OS | Version | Status | Fixed in |
|---|---|---|---|
| debian | bookworm | fixed | 2.4.67-1~deb12u2 |
| debian | bullseye | fixed | 2.4.67-1~deb11u1 |
| debian | forky | fixed | 2.4.67-1 |
| debian | sid | fixed | 2.4.67-1 |
| debian | trixie | fixed | 2.4.67-1~deb13u2 |
| sles | affected | |
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| apache | http_server | {"endExcluding":"2.4.67"} | 2.4.67 |
References
CWEs
CWE-269
Verify integrity in audit chain (admin only). AS-IS.