Remote File Access Vulnerability in Apache HTTP Server by Apache Software Foundation
CVE-2026-58415

Currently unrated

Key Information:

Vendor

Apache

Vendor
CVE Published:
1 October 2026

What is CVE-2026-58415?

A vulnerability in the Apache HTTP Server's mod_dav_fs module allows remote clients to access internal state files, which are meant to be restricted. Specifically, this flaw permits unauthorized parties to execute GET requests on the .DAV state directory, exposing WebDAV dead properties of resources that they are not authorized to manipulate. This issue affects all versions of the server between 2.4.0 and 2.4.68 across all platforms, posing a risk of sensitive information disclosure.

Affected Version(s)

Apache HTTP Server 2.4.0 <= 2.4.68

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

이지웅 (kimchunbok)
sungbyeongchan
.