Improper access control in Apache HTTP Server - CVE-2026-58415
Published: October 1, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose WebDAV dead properties of resources they cannot author.
The vulnerability exists due to improper access control in mod_dav_fs when requesting the .DAV state directory through a GET request. A remote attacker can send a GET request for the .DAV state directory to disclose WebDAV dead properties of resources they cannot author.