← Back to CVE search

CVE-2026-44119

Apache HTTP Server

Description

Improper Privilege Management vulnerability in Apache HTTP Server 2.4.67 and earlier allows local .htaccess authors to read files with the privileges of the httpd user. This issue affects Apache HTTP Server: from through 2.4.67. Users are recommended to upgrade to version 2.4.68, which fixes the issue.

CVSS 5.5EPSS 0.17700000000000002%Risk 0.56
View source
Published
2026-06-08 16:16:40
Affected versions
<2.4.68
Type
Core software
Last modified
2026-07-23 07:10:00
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N