Back to Security Advisories

Security : CVE-2026-24072 : Apache HTTP Server: mod_rewrite elevation of privileges via ap_expr

An escalation-of-privilege bug in various modules in Apache HTTP Server 2.4.66 and earlier allows local .htaccess authors to read files with the privileges of the httpd user. 

High
CloudLinux cPanel Imunify360

Default Update CMD

sudo /scripts/upcp --force

Situation

An escalation-of-privilege bug in various modules in Apache HTTP Server 2.4.66 and earlier allows local .htaccess authors to read files with the privileges of the httpd user. 

Users are recommended to upgrade to version 2.4.67, which fixes this issue.

Impact

Users are recommended to upgrade to version 2.4.67, which fixes this issue.

We have pushed out a patch for the following additional CVE’s: 

You can find more information on all of the above in our Change Logs: Easy Apache 4 Change logs

Call to Action

AlmaLinux

Please run the following command to update EasyApache 4: 

# dnf clean all

# dnf makecache

# dnf -y update ea-apache*

Please run the following command to update EasyApache 4: 

# yum update ea-apache24 –enablerepo=cl-ea4-testing

Please run the following command to update EasyApache 4: 

# yum update ea-apache24 –enablerepo=imunify360-ea-php-hardened-beta

Ubuntu

Please run the following command to update EasyApache 4: 

# apt update

# apt install –only-upgrade “ea-apache24*”

How to Apply the Fix

Update the affected packages on your server to the patched release, then restart the relevant services.

sudo /scripts/upcp --force

Check your system for vulnerabilities

अपना उत्पाद और ऑपरेटिंग सिस्टम चुनें ताकि आपके लिए लागू सटीक फिक्स कमांड देख सकें।

Check Your System