CVE-2026-79768
Received Received - Intake

Path Equivalence in Apache HTTP Server mod_userdir

Vulnerability report for CVE-2026-79768, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-01

Last updated on: 2026-10-01

Assigner: Apache Software Foundation

Description

Path equivalence: '/./' (single dot directory) vulnerability in Apache HTTP Server's mod_userdir module when configured with absolute non-wildcard UserDir directive (the 2nd form in https://httpd.apache.org/docs/2.4/mod/mod_userdir.html#userdir) This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-01
Last Modified
2026-10-01
Generated
2026-10-01
AI Q&A
2026-10-01
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
apache http_server From 2.4.0 (inc) to 2.4.68 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-55 The product accepts path input in the form of single dot directory exploit ('/./') without appropriate validation, which can lead to ambiguous path resolution and allow an attacker to traverse the file system to unintended locations or access arbitrary files.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in Apache HTTP Server's mod_userdir module allows path equivalence attacks using '/./' (single dot directory) when the UserDir directive is set to an absolute non-wildcard path. This could let attackers access user directories in unintended ways.

Detection Guidance

This vulnerability can be detected by checking Apache HTTP Server versions between 2.4.0 and 2.4.68. Use commands like 'httpd -v' or 'apache2 -v' to check the installed version. If the version falls within this range, the system is vulnerable.

Impact Analysis

If you use Apache HTTP Server with mod_userdir configured as described, attackers might bypass intended access controls and access user directories they shouldn't. This could lead to unauthorized data exposure or information disclosure.

Mitigation Strategies

Upgrade Apache HTTP Server to version 2.4.69 or later to address the vulnerability in mod_userdir module.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-79768. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart