CVE-2026-24072: Apache HTTP Server: mod_rewrite elevation of privileges via ap_expr
An escalation of privilege bug in various modules in Apache HTTP 2.4.66 and earlier allows local .htaccess authors to read files with the privileges of the httpd user.
Users are recommended to upgrade to version 2.4.67, which fixes this issue.
Other sources
Apache HTTP Server: modrewrite elevation of privileges via apexpr
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2.4.67-1 - Upgrade
Upgrade
Apache HTTP Serverto a version that resolves this vulnerability.Fixed in 2.4.67 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch CVE-2026-24072
Event History
Frequently Asked Questions
What is the severity of CVE-2026-24072?
CVE-2026-24072 has been rated as having a moderate severity level due to the potential for privilege escalation.
How do I fix CVE-2026-24072?
To fix CVE-2026-24072, upgrade to Apache HTTP Server version 2.4.67 or later.
What versions of Apache HTTP Server are affected by CVE-2026-24072?
CVE-2026-24072 affects all versions of Apache HTTP Server up to and including 2.4.66.
What impact does CVE-2026-24072 have on web server security?
CVE-2026-24072 allows local .htaccess authors to read files with the permissions of the httpd user, which can lead to unauthorized information disclosure.
Is there a workaround for CVE-2026-24072 if I cannot upgrade?
There are no recommended workarounds for CVE-2026-24072; upgrading to the latest version is necessary to mitigate the vulnerability.