CVE Tools

CVE-2026-42535

Apache HTTP Server: mod_dav_fs protected directory access

Published: Jun 8, 2026Updated: Jul 23, 2026 Sources: CVE List NVDCWE-668

Description

A path handling issue in mod_dav_fs in Apache 2.4.67 and earlier allows a WebDAV content author to directly manipulate trusted DAV property databases, potentially causing child process crashes. Users are recommended to upgrade to version 2.4.68, which fixes this issue.

In plain language

AI Worth attention

This is a serious bug in Apache HTTP Server that could let a remote attacker crash the web server without any login by abusing WebDAV features; if you use WebDAV (mod_dav_fs), you should act.

Executive summary

CVE-2026-42535 is an unauthenticated denial-of-service in Apache HTTP Server’s mod_dav_fs where a network attacker can manipulate WebDAV properties to corrupt/alter the DAV property database, potentially crashing child processes.

If affected, business impact
Web site outageLoss of customer accessService disruptionPotential cascading downtime

What to do now

  1. Check whether your Apache configuration uses mod_dav_fs / WebDAV (for example, any enabled WebDAV filesystem/DAV directives or mounts).
  2. Determine your current Apache HTTP Server version.
  3. Upgrade Apache HTTP Server to 2.4.68 (this is the fixed version).
  4. If you cannot upgrade immediately, disable or restrict WebDAV (mod_dav_fs) so the vulnerable code path is not reachable, and plan an upgrade as soon as possible.
Patch / advisory Usually a quick update

CVSS Vector Breakdown

AV:NAC:LPR:NUI:NS:UC:NI:HA:H
Exploitability
AV:NAttack Vector
Network
AC:LAttack Complexity
Low
PR:NPrivileges Required
None
UI:NUser Interaction
None
Scope
S:UScope
Unchanged
Impact
C:NConfidentiality
None
I:HIntegrity
High
A:HAvailability
High

Weaknesses

Affected Products

apache
oss-project·USaka apache http server, apache httpd

Exploitability

Official Patch Available

References

Unlock Complete Vulnerability Intelligence

Get the full picture for CVE-2026-42535 and every CVE in our database. Create a free account — no credit card required.

Create Free Account
Plain-language analysis
Impact assessment and exploitation scenario in plain English
Attack graph visualization
Interactive attack path and kill chain mapping
Exploit details & PoC links
ExploitDB, Metasploit, GitHub PoCs with direct links
Nuclei scanner templates
Ready-to-use vulnerability scanner templates
Full remediation guide
Patch instructions, workarounds, and compliance impact
Interactive AI chat
Ask questions about this vulnerability in natural language
Related vulnerabilities
Semantically similar CVEs and attack patterns
REST API & MCP access
Integrate vulnerability data into your workflows