Improper privilege management in Apache HTTP Server - CVE-2026-44119
Published: June 8, 2026
Apache HTTP Server
Detailed vulnerability description
The vulnerability allows a local user to disclose sensitive information.
The vulnerability exists due to improper privilege management in expression handling in .htaccess across multiple modules when processing .htaccess expressions. A local user can author .htaccess expressions to disclose sensitive information.
The issue allows reading files with the privileges of the httpd user.