Description
Path equivalence: '/./' (single dot directory) vulnerability in Apache HTTP Server's mod_userdir module when configured with absolute non-wildcard UserDir directive (the 2nd form in https://httpd.apache.org/docs/2.4/mod/mod_userdir.html#userdir)



This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.
Published: 2026-10-01
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: Information Disclosure
Action: Patch
AI Analysis

Impact

The vulnerability exploits a path equivalence condition in Apache HTTP Server’s mod_userdir module, where the '/./' (single dot directory) notation is treated as equivalent to the parent directory. When mod_userdir is configured with an absolute non-wildcard UserDir directive, an attacker can supply specially crafted URLs to access files outside the intended user directory and potentially retrieve content from the server’s file system. This results in unauthorized disclosure of sensitive files that may contain configuration data or user data, compromising confidentiality. The weakness is identified as CWE-55, which denotes improper handling of path equivalence and precursors to directory traversal faults.

Affected Systems

All installations of Apache HTTP Server versions 2.4.0 through 2.4.68 that enable the mod_userdir module with an absolute non‑wildcard UserDir directive are affected. The vulnerability does not require any additional services or modules beyond the standard mod_userdir configuration and therefore applies to any web server instance using this directive within the stated version range.

Risk and Exploitability

The vulnerability is remotely exploitable via standard HTTP requests, as an attacker only needs to direct a URI containing the vulnerable path equivalence pattern to the affected server. The EPSS score is not available, indicating that the exploitation likelihood is not quantified at this time, but the absence of a KEV listing suggests it has not been documented as a known exploited vulnerability. Nonetheless, the remote nature of the attack vector, the ability to gain access to arbitrary files, and the broad version scope imply a high potential impact for any affected deployment. Deployers should therefore treat this as a high‑risk condition until mitigated.

Generated by OpenCVE AI on October 1, 2026 at 18:17 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to Apache HTTP Server 2.4.69 or later, which contains a patch that removes the path equivalence flaw in mod_userdir.
  • Modify the UserDir configuration to avoid absolute non‑wildcard paths; use relative or wildcard patterns or remove the directive entirely if user directory access is not required.
  • If an update cannot be performed immediately, disable mod_userdir or restrict the directory it serves to a minimal set of files to limit potential exposure.

Generated by OpenCVE AI on October 1, 2026 at 18:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 01 Oct 2026 16:30:00 +0000

Type Values Removed Values Added
Description Path equivalence: '/./' (single dot directory) vulnerability in Apache HTTP Server's mod_userdir module when configured with absolute non-wildcard UserDir directive (the 2nd form in https://httpd.apache.org/docs/2.4/mod/mod_userdir.html#userdir) This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.
Title Apache HTTP Server: mod_userdir information disclosure
Weaknesses CWE-55
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-10-01T20:09:34.983Z

Reserved: 2026-08-25T14:25:35.993Z

Link: CVE-2026-79768

cve-icon Vulnrichment

Updated: 2026-10-01T19:40:01.858Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-10-01T17:17:31.910

Modified: 2026-10-01T20:30:25.943

Link: CVE-2026-79768

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T18:30:11Z

Weaknesses
  • CWE-55

    Path Equivalence: '/./' (Single Dot Directory)