Description
Improper Privilege Management vulnerability in Apache HTTP Server 2.4.67 and earlier allows local .htaccess authors to read files with the privileges of the httpd user. This issue affects Apache HTTP Server: from through 2.4.67. Users are recommended to upgrade to version 2.4.68, which fixes the issue.
Problem types
CWE-269 Improper Privilege Management
Product status
2.4.0 (semver)
Timeline
| 2026-05-05: | reported |
| 2026-06-05: | fixed in 2.4.x by r1935017 |
| 2026-06-08: | 2.4.68 released |
Credits
Lucian Nitescu
as3617 (@real_as3617) at ENKI Whitehat
Zhang San
Martin Petrák
joaovicdev
Rooting | Lucas Torres
R4mbb of KRsecurity
gggggggga@Xiaomi ShadowBlade Security Lab
NikKrian of H3C Security Center(h3c.com)
lokerxx
References
www.openwall.com/lists/oss-security/2026/06/08/11
httpd.apache.org/security/vulnerabilities_24.html