Executive brief
A vulnerability in the Apache HTTP Server's WebDAV module could allow an authorized content author to interfere with internal property databases. This could lead to service instability or crashes of the server's background processes, potentially disrupting website availability. Organizations using WebDAV for remote file management should update to the latest version to ensure service reliability.
Technical details
A path handling vulnerability (CWE-668) exists in the mod_dav_fs module of the Apache HTTP Server. The flaw allows an authenticated WebDAV content author to bypass intended restrictions and directly manipulate trusted DAV property databases. This unauthorized access is achieved through improper path handling, which can be leveraged to corrupt database files or trigger child process crashes (denial of service). The issue is reachable over the network by any user with permissions to author content via WebDAV. A fix is available in Apache HTTP Server version 2.4.68.
Affected products
- Apache HTTP Server 2.4.0 through 2.4.67
Timeline
- 2026-04-27: disclosed: Report received by Apache security team
- 2026-06-05: patched: Fixed in 2.4.x branch
- 2026-06-08: advisory: Public advisory released with version 2.4.68