CVE-2026-44119
published 2026-06-08CVE-2026-44119: Improper Privilege Management vulnerability in Apache HTTP Server 2.4.67 and earlier allows local .htaccess authors to read files with the privileges of the…
PriorityP426medium5.5CVSS 3.1
AVLACLPRLUINSUCHINAN
EPSS
0.17%
6.7th percentile
Improper Privilege Management vulnerability in Apache HTTP Server 2.4.67 and earlier allows local .htaccess authors to read files with the privileges of the httpd user.
This issue affects Apache HTTP Server: from through 2.4.67.
Users are recommended to upgrade to version 2.4.68, which fixes the issue.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | http_server | >= 2.4.0 < 2.4.68 | 2.4.68 |
| apache | httpd | — | — |
| apache_software_foundation | apache_http_server | 2.4.0 – 2.4.67 | — |
| ubuntu | apache2 | — | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
vendor_ubuntu9.8CRITICAL
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Apache HTTP Server vulnerabilities
vendor_ubuntu·2026-07-08·CVSS 9.8
CVE-2026-44119 [CRITICAL] Apache HTTP Server vulnerabilities
Title: Apache HTTP Server vulnerabilities
Summary: Several security issues were fixed in Apache HTTP Server.
It was discovered that Apache HTTP Server's mod_ldap module incorrectly
handled memory when processing per-directory configurations. An attacker
could use this issue to cause the server to crash, resulting in a denial of
service, or possibly execute arbitrary code. (CVE-2026-29167)
It was discovered that Apache HTTP Server's mod_proxy_ftp module
incorrectly handled HTML generation for FTP directory listings. A remote
attacker could possibly use this issue to inject arbitrary web script or
HTML. (CVE-2026-29170)
It was discovered that Apache HTTP Server's mod_proxy_html module
incorrectly handled certain content from an untrusted backend. A remote
attacker could possibly use this
Red Hat
httpd: Apache HTTP Server: Local .htaccess authors can read files with httpd user privileges
vendor_redhat·2026-06-08·CVSS 5.5
CVE-2026-44119 [MEDIUM] CWE-266 httpd: Apache HTTP Server: Local .htaccess authors can read files with httpd user privileges
httpd: Apache HTTP Server: Local .htaccess authors can read files with httpd user privileges
Improper Privilege Management vulnerability in Apache HTTP Server 2.4.67 and earlier allows local .htaccess authors to read files with the privileges of the httpd user.
This issue affects Apache HTTP Server: from through 2.4.67.
Users are recommended to upgrade to version 2.4.68, which fixes the issue.
A flaw was found in Apache HTTP Server. This improper privilege management vulnerability allows local .htaccess authors to read files with the privileges of the httpd user. This could lead to unauthorized information disclosure.
Package: httpd (Red Hat Enterprise Linux 10) - Fix deferred
Package: httpd (Red Hat Enterprise Linux 6) - Fix deferred
Package: httpd (Red Hat Enterprise Linux 7) - Fix
GHSA
Improper Privilege Management vulnerability in Apache HTTP Server 2.4.67 and earlier allows local .htaccess authors to read files with the privileges of the httpd user.
ghsa_unreviewed·2026-06-08
CVE-2026-44119 [MEDIUM] CWE-269 Improper Privilege Management vulnerability in Apache HTTP Server 2.4.67 and earlier allows local .htaccess authors to read files with the privileges of the httpd user.
Improper Privilege Management vulnerability in Apache HTTP Server 2.4.67 and earlier allows local .htaccess authors to read files with the privileges of the httpd user.
This issue affects Apache HTTP Server: from through 2.4.67.
Users are recommended to upgrade to version 2.4.68, which fixes the issue.
VulDB
Apache HTTP Server up to 2.4.67 htaccess information disclosure (EUVD-2026-35094 / Nessus ID 319665)
vuldb·2026-06-08
CVE-2026-44119 [LOW] Apache HTTP Server up to 2.4.67 htaccess information disclosure (EUVD-2026-35094 / Nessus ID 319665)
A vulnerability labeled as problematic has been found in Apache HTTP Server up to 2.4.67. Affected by this vulnerability is an unknown functionality of the component htaccess Handler. The manipulation results in information disclosure.
This vulnerability is cataloged as CVE-2026-44119. The attack must be initiated from a local position. There is no exploit available.
The affected component should be upgraded.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-44119 httpd: Apache HTTP Server: Local .htaccess authors can read files with httpd user privileges [fedora-all]
bugzilla·2026-06-12·CVSS 5.5
CVE-2026-44119 [MEDIUM] CVE-2026-44119 httpd: Apache HTTP Server: Local .htaccess authors can read files with httpd user privileges [fedora-all]
CVE-2026-44119 httpd: Apache HTTP Server: Local .htaccess authors can read files with httpd user privileges [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-44119 httpd: Apache HTTP Server: Local .htaccess authors can read files with httpd user privileges
bugzilla·2026-06-08·CVSS 5.5
CVE-2026-44119 [MEDIUM] CVE-2026-44119 httpd: Apache HTTP Server: Local .htaccess authors can read files with httpd user privileges
CVE-2026-44119 httpd: Apache HTTP Server: Local .htaccess authors can read files with httpd user privileges
Improper Privilege Management vulnerability in Apache HTTP Server 2.4.67 and earlier allows local .htaccess authors to read files with the privileges of the httpd user.
This issue affects Apache HTTP Server: from through 2.4.67.
Users are recommended to upgrade to version 2.4.68, which fixes the issue.
2026-06-08
Published