CVE-2026-44119: Apache HTTP Server: escalation of privilege through expressions in .htaccess in multiple modules
Improper Privilege Management vulnerability in Apache HTTP Server 2.4.67 and earlier allows local .htaccess authors to read files with the privileges of the httpd user.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/apache2to a version that resolves this vulnerability.Fixed in 2.4.67-1~deb11u3Fixed in 2.4.68-1~deb12u1Fixed in 2.4.68-1~deb13u1Fixed in 2.4.68-1 - Upgrade
Upgrade
Apache HTTP Serverto a version that resolves this vulnerability.Fixed in 2.4.68
Event History
Frequently Asked Questions
What is the severity of CVE-2026-44119?
CVE-2026-44119 has a risk level of 34, indicating a significant security concern.
How do I fix CVE-2026-44119?
To fix CVE-2026-44119, upgrade Apache HTTP Server to version 2.4.68 or later.
What are the impacts of CVE-2026-44119?
CVE-2026-44119 allows local .htaccess authors to read files with the privileges of the httpd user, leading to potential data exposure.
Which versions of Apache HTTP Server are affected by CVE-2026-44119?
Apache HTTP Server versions up to and including 2.4.67 are affected by CVE-2026-44119.
Is it necessary to patch for CVE-2026-44119?
Yes, patching for CVE-2026-44119 is crucial to prevent unauthorized access and privilege escalation.