CVE-2026-79768
Received
Received - Intake
Path Equivalence in Apache HTTP Server mod_userdir
Vulnerability report for CVE-2026-79768, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-10-01
Last updated on: 2026-10-01
Assigner: Apache Software Foundation
Description
Description
Path equivalence: '/./' (single dot directory) vulnerability in Apache HTTP Server's mod_userdir module when configured with absolute non-wildcard UserDir directive (the 2nd form in https://httpd.apache.org/docs/2.4/mod/mod_userdir.html#userdir)
This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| apache | http_server | From 2.4.0 (inc) to 2.4.68 (inc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-55 | The product accepts path input in the form of single dot directory exploit ('/./') without appropriate validation, which can lead to ambiguous path resolution and allow an attacker to traverse the file system to unintended locations or access arbitrary files. |