← back
CVE-2026-24072highCWE-269

Apache HTTP Server: mod_rewrite elevation of privileges via ap_expr

21Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 8.8epss 0.7%
from disclosure to weapon1 days
Published on NVDMay 4
1st PoC+1d
exploitation probability
0.7%top 52% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
An escalation of privilege bug in various modules in Apache HTTP 2.4.66 and earlier allows local .htaccess authors to read files with the privileges of the httpd user. Users are recommended to upgrade to version 2.4.67, which fixes this issue.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.