Path Equivalence Vulnerability in Apache HTTP Server's UserDir Module
CVE-2026-79768

Currently unrated

Key Information:

Vendor

Apache

Vendor
CVE Published:
1 October 2026

What is CVE-2026-79768?

A vulnerability exists in the Apache HTTP Server’s mod_userdir module due to improper handling of path equivalence with the '/./' sequence. When configured with an absolute non-wildcard UserDir directive, this flaw may allow attackers to bypass access controls and potentially gain unauthorized access to user directories. Administrators are advised to evaluate their configurations and apply mitigations to safeguard against exploitation.

Affected Version(s)

Apache HTTP Server 2.4.0 <= 2.4.68

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Vlatko Kosturjak, Marlink Cyber
.