← Browse

CVE-2026-42535

Medium

Elevated severity or exploit probability.

CVSS base
9.1 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
EPSS — probability of exploitation (30 days)
0.7%
51.5th percentile
CISA KEV
Not listed
Weakness / dates
CWE-668
Published 2026-06-08 · modified 2026-07-23

Description

A path handling issue in mod_dav_fs in Apache 2.4.67 and earlier allows a WebDAV content author to directly manipulate trusted DAV property databases, potentially causing child process crashes. Users are recommended to upgrade to version 2.4.68, which fixes this issue.

Affected

apache

References

Official: NVD · CVE.org