
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-79768 is a path equivalence vulnerability (CWE-55) in Apache HTTP Server's mod_userdir module, triggered when the server is configured with an absolute non-wildcard UserDir directive. By crafting requests containing /./ (single dot directory) sequences, unauthenticated remote attackers can bypass directory access restrictions and access files that should be protected. The vulnerability affects Apache HTTP Server versions 2.4.0 through 2.4.68 and was disclosed on October 1, 2026. It carries a CVSS v3.1 base score of 5.3 (Medium) (GitHub Advisory, Apache Advisory).
The root cause is improper path normalization in the mod_userdir module when handling the second form of the UserDir directive — an absolute, non-wildcard path (e.g., UserDir /var/www/users). When a request URI contains a /./ sequence, the server fails to correctly resolve the canonical path before applying access controls, allowing the path equivalence bypass (CWE-55). An attacker can send a crafted HTTP GET request with a /./ segment in the URL to traverse into directories that the UserDir directive is intended to restrict. No authentication or special privileges are required, and the attack is network-accessible with low complexity (GitHub Advisory, Apache Advisory).
Successful exploitation results in unauthorized read access to files within user directories that are protected by the absolute non-wildcard UserDir configuration, constituting an information disclosure risk. The confidentiality impact is rated low, with no integrity or availability impact, meaning attackers cannot modify or delete files through this vector alone. However, exposed files could include sensitive user data, configuration files, or credentials that enable further lateral movement or privilege escalation (GitHub Advisory).
As of the disclosure date (October 1, 2026), there is no public proof-of-concept exploit code and no evidence of active in-the-wild exploitation (GitHub Advisory). The vulnerability is automatable (no user interaction required) and exploitable by unauthenticated network attackers, which lowers the barrier for opportunistic exploitation. The EPSS score is reported as 0.0 at time of publication, and the CVE is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (GitHub Advisory).
mod_userdir enabled with an absolute non-wildcard UserDir directive (e.g., UserDir /srv/users) using tools like Shodan, Censys, or active HTTP fingerprinting.mod_userdir URL patterns (e.g., http://target/~username/) to confirm the module is active and enumerate accessible user directories././ sequence in the URI path to exploit the normalization bypass, for example: GET /~username/./protected-file HTTP/1.1.UserDir access controls, the response will return the content of files that should be restricted, achieving unauthorized information disclosure (GitHub Advisory).mod_userdir paths (e.g., /~username/) containing /./ sequences in the URI; unusual access patterns to user directory URLs from external or unexpected IP addresses.access_log) showing requests with /./ in the path targeting ~username URLs, particularly returning HTTP 200 responses for files not normally accessible; repeated probing of multiple usernames in short succession.UserDir directive configured with an absolute non-wildcard path in httpd.conf or included configuration files, confirming the vulnerable configuration is active.The primary remediation is to upgrade Apache HTTP Server to a version newer than 2.4.68, which contains the fix for this vulnerability (Apache Advisory). If immediate patching is not feasible, administrators should review UserDir configurations and avoid using absolute non-wildcard UserDir directives, or supplement them with additional <Directory> access control blocks to restrict unauthorized access. Network-level controls such as WAF rules blocking requests containing /./ sequences in URI paths can serve as an interim mitigation (GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."