Remote File Access Vulnerability in Apache HTTP Server by Apache Software Foundation
CVE-2026-58415
Currently unrated
What is CVE-2026-58415?
A vulnerability in the Apache HTTP Server's mod_dav_fs module allows remote clients to access internal state files, which are meant to be restricted. Specifically, this flaw permits unauthorized parties to execute GET requests on the .DAV state directory, exposing WebDAV dead properties of resources that they are not authorized to manipulate. This issue affects all versions of the server between 2.4.0 and 2.4.68 across all platforms, posing a risk of sensitive information disclosure.
Affected Version(s)
Apache HTTP Server 2.4.0 <= 2.4.68