Description
Internal state files accessible to external parties in mod_dav_fs in Apache Software Foundation Apache HTTP Server before 2.4.69 on all platforms allows a remote client to read WebDAV dead properties of resources it cannot author via a GET request for the .DAV state directory



This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.
Published: 2026-10-01
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: Read-Only Access to WebDAV Dead Properties
Action: Patch
AI Analysis

Impact

Apache HTTP Server versions prior to 2.4.69 on all platforms include a flaw in the mod_dav_fs component that allows remote clients to access internal state files. By issuing a simple GET request to the ".DAV" state directory, an attacker can retrieve the dead properties of WebDAV resources that the client cannot normally modify. This exposure allows the attacker to read the dead properties of WebDAV resources.

Affected Systems

The vulnerability affects Apache HTTP Server releases from 2.4.0 through 2.4.68. All operating systems that run these versions are potentially impacted, regardless of platform.

Risk and Exploitability

The vulnerability can be exploited by a remote client over HTTP. The CVSS score is 5.3, indicating a moderate severity. EPSS score is not available, and the issue is not listed in the CISA KEV catalog.

Generated by OpenCVE AI on October 1, 2026 at 22:05 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Apache HTTP Server to version 2.4.69 or newer.
  • If an upgrade is not immediately possible, restrict or disable access to the ".DAV" state directory by configuring appropriate access controls or removing the directory from the web server’s document root.
  • Ensure that WebDAV is only enabled on resources that require it and apply authentication or authorization rules to prevent unauthenticated users from reading state files.

Generated by OpenCVE AI on October 1, 2026 at 22:05 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 21:30:00 +0000

Type Values Removed Values Added
References

Thu, 01 Oct 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 01 Oct 2026 18:00:00 +0000

Type Values Removed Values Added
First Time appeared Apache
Apache apache Http Server
Vendors & Products Apache
Apache apache Http Server

Thu, 01 Oct 2026 16:30:00 +0000

Type Values Removed Values Added
Description Internal state files accessible to external parties in mod_dav_fs in Apache Software Foundation Apache HTTP Server before 2.4.69 on all platforms allows a remote client to read WebDAV dead properties of resources it cannot author via a GET request for the .DAV state directory This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.
Title Apache HTTP Server: mod_dav_fs property database read access
Weaknesses CWE-552
References

Subscriptions

Apache Apache Http Server
cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-10-01T20:09:26.575Z

Reserved: 2026-06-30T18:21:24.562Z

Link: CVE-2026-58415

cve-icon Vulnrichment

Updated: 2026-10-01T20:09:26.575Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-10-01T17:17:29.260

Modified: 2026-10-01T21:17:22.873

Link: CVE-2026-58415

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T22:15:13Z

Weaknesses
  • CWE-552

    Files or Directories Accessible to External Parties