CVE-2026-24072 PUBLISHED

Apache HTTP Server: mod_rewrite elevation of privileges via ap_expr

Assigner: apache
Reserved: 21.01.2026 Published: 04.05.2026 Updated: 05.05.2026

An escalation of privilege bug in various modules in Apache HTTP 2.4.66 and earlier allows local .htaccess authors to read files with the privileges of the httpd user.

Users are recommended to upgrade to version 2.4.67, which fixes this issue.

Product Status

Vendor Apache Software Foundation
Product Apache HTTP Server
Versions Default: unaffected
  • affected from 0 to 2.4.66 (incl.)

Credits

  • y7syeu finder

References

Problem Types

  • CWE-269 Improper Privilege Management CWE