An escalation of privilege bug in various modules in Apache HTTP 2.4.66 and earlier allows local .htaccess authors to read files with the privileges of the httpd user.
Users are recommended to upgrade to version 2.4.67, which fixes this issue.
Loading...
Score 8.8 from GitHub Security Advisory (severity: HIGH) published 2026-05-04. NVD baseline CVSS 8.8; sources differ by 0.0.
An escalation of privilege bug in various modules in Apache HTTP 2.4.66 and earlier allows local .htaccess authors to read files with the privileges of the httpd user.
Users are recommended to upgrade to version 2.4.67, which fixes this issue.
May 4, 2026
May 4, 2026
These vendors published their own advisory mentioning this CVE — often with vendor-specific remediation steps + affected product lists not in NVD.
See which npm, PyPI, Go, and Maven packages are affected by CVE-2026-24072
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.
redhat · ubuntu