← לוח פגיעויות

CVE-2026-24072

גבוהה 8.8

תיאור (מקור, אנגלית)

An escalation of privilege bug in various modules in Apache HTTP 2.4.66 and earlier allows local .htaccess authors to read files with the privileges of the httpd user. Users are recommended to upgrade to version 2.4.67, which fixes this issue.

מדדים

CVSS 3.1
8.8 (HIGH) מקור הציון: CNA CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS — סבירות ניצול
1% (אחוזון 000) נכון ל-31/7/2026
CWE
CWE-269

מוצרים מושפעים

apache: http server

קישורים