CVE-2026-79768: Apache HTTP Server: mod_userdir information disclosure
Published Oct 1, 2026
·Updated
Path equivalence: '/./' (single dot directory) vulnerability in Apache HTTP Server's moduserdir module when configured with absolute non-wildcard UserDir directive (the 2nd form in https://httpd.apache.org/docs/2.4/mod/moduserdir.html#userdir)
This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.
Affected Software
1 affected component
Apache HTTP Server>=2.4.0<=2.4.68
Event History
Oct 1, 2026
CVE Published
via MITRE·04:18 PM
Data Sourced
via MITRE·04:18 PM
DescriptionWeakness
Data Sourced
via NVD·05:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which Apache HTTP Server deployments are affected?
Apache HTTP Server versions 2.4.0 through 2.4.68 are affected when mod_userdir is configured with an absolute, non-wildcard UserDir directive.
2
What does an attacker need to send to trigger the issue?
The issue involves path equivalence using a '/./' single-dot directory path. The affected configuration prerequisite is an absolute non-wildcard UserDir directive in mod_userdir.