https://seclists.org/oss-sec/2026/q2/840: CVE-2026-44119: Apache HTTP Server: escalation of privilege through expssions in .htaccess in multiple modules
Published Jun 8, 2026
·Updated
Affected Software
1 affected component
Apache HTTP Server>=2.4.0<=2.4.67
Frequently Asked Questions
1
What is the severity of CVE-2026-44119?
The severity of CVE-2026-44119 is rated as moderate.
2
Which versions of Apache HTTP Server are affected by CVE-2026-44119?
Apache HTTP Server versions 2.4.0 through 2.4.67 are affected by CVE-2026-44119.
3
What kind of vulnerability is CVE-2026-44119?
CVE-2026-44119 is an improper privilege management vulnerability.
4
How does CVE-2026-44119 allow privilege escalation?
CVE-2026-44119 allows local .htaccess authors to read files with the privileges of the httpd user.
5
How can I mitigate CVE-2026-44119?
To mitigate CVE-2026-44119, ensure you update Apache HTTP Server to version 2.4.68 or later.