Path traversal in Apache HTTP Server - CVE-2026-79768
Published: October 1, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to improper path canonicalization in the mod_userdir module when handling requests containing a "/./" path. A remote attacker can send a specially crafted request to disclose sensitive information.
Only configurations using an absolute non-wildcard UserDir directive are affected.