CVE-2026-42535
Apache HTTP Server: mod_dav_fs protected directory access
Description
A path handling issue in mod_dav_fs in Apache 2.4.67 and earlier allows a WebDAV content author to directly manipulate trusted DAV property databases, potentially causing child process crashes. Users are recommended to upgrade to version 2.4.68, which fixes this issue.
In plain language
AI Worth attentionThis is a serious bug in Apache HTTP Server that could let a remote attacker crash the web server without any login by abusing WebDAV features; if you use WebDAV (mod_dav_fs), you should act.
CVE-2026-42535 is an unauthenticated denial-of-service in Apache HTTP Server’s mod_dav_fs where a network attacker can manipulate WebDAV properties to corrupt/alter the DAV property database, potentially crashing child processes.
What to do now
- Check whether your Apache configuration uses mod_dav_fs / WebDAV (for example, any enabled WebDAV filesystem/DAV directives or mounts).
- Determine your current Apache HTTP Server version.
- Upgrade Apache HTTP Server to 2.4.68 (this is the fixed version).
- If you cannot upgrade immediately, disable or restrict WebDAV (mod_dav_fs) so the vulnerable code path is not reachable, and plan an upgrade as soon as possible.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:NUser InteractionS:UScopeC:NConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
References
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-42535 and every CVE in our database. Create a free account — no credit card required.
Create Free Account