Güvenlik Danışarlıklarına Dön

Security: CVE-2026-24072: Apache HTTP Server: mod_rewrite elevation of privileges via ap_expr

An escalation-of-privilege bug in various modules in Apache HTTP Server 2.4.66 and earlier allows local .htaccess authors to read files with the privileges of the httpd user. 

High 8.8 CVSS
CloudLinux cPanel Imunify360

Varsayılan Güncelleme Komutu

yum update ea-apache24*   # or WHM → EasyApache 4 → Update

SharedLicense lisansı altında bunun anlamı

Your SharedLicense license itself is not affected — this is a vulnerability in CloudLinux, cPanel, Imunify360 software, not in licensing. Licenses continue to work during and after the update; there is no need to re-issue or re-activate anything. If you resell CloudLinux, cPanel, Imunify360 under your own brand, patch client servers too — unpatched installs put your reputation at risk, not your license.

Situation

An escalation-of-privilege bug in various modules in Apache HTTP Server 2.4.66 and earlier allows local .htaccess authors to read files with the privileges of the httpd user. 

Users are recommended to upgrade to version 2.4.67, which fixes this issue.

Impact

Users are recommended to upgrade to version 2.4.67, which fixes this issue.

We have pushed out a patch for the following additional CVE’s: 

You can find more information on all of the above in our Change Logs: Easy Apache 4 Change logs

Call to Action

AlmaLinux

Please run the following command to update EasyApache 4: 

# dnf clean all

# dnf makecache

# dnf -y update ea-apache*

CloudLinux

Please run the following command to update EasyApache 4: 

# yum update ea-apache24 –enablerepo=cl-ea4-testing

Imunify360

Please run the following command to update EasyApache 4: 

# yum update ea-apache24 –enablerepo=imunify360-ea-php-hardened-beta

Ubuntu

Please run the following command to update EasyApache 4: 

# apt update

# apt install –only-upgrade “ea-apache24*”

Sıkça Sorulan Sorular

What is CVE-2026-24072?
An escalation of privilege bug in various modules in Apache HTTP 2.4.66 and earlier allows local .htaccess authors to read files with the privileges of the httpd user. Users are recommended to upgrade to version 2.4.67, which fixes this issue.
Is CVE-2026-24072 being exploited in the wild?
No confirmed exploitation is recorded. The EPSS model estimates a 0.65% probability of exploitation within the next 30 days — patch on your normal schedule.
How do I fix CVE-2026-24072?
Update CloudLinux, cPanel, Imunify360 to the patched release.Then confirm the running version matches the patched release listed above.
Why does this advisory list several CVEs?
One vendor release fixed multiple vulnerabilities. This advisory covers CVE-2026-24072, CVE-2026-33006, CVE-2026-28780, CVE-2026-29168, CVE-2026-29169, CVE-2026-33007, CVE-2026-33523, CVE-2026-33857, CVE-2026-34032, CVE-2026-34059 — updating to the patched release resolves all of them at once.

Sisteminizi güvenlik açıkları açısından kontrol edin

Size uygun tam düzeltme komutlarını görmek için ürününüzü ve işletim sisteminizi seçin.

Sisteminizi Kontrol Edin