high CVSS 7.5

CVE-2026-47360·Apache vulnerability

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache HTTP Server's mod_session_cookie module.   When SessionCookieRemove changes across internal redirects, the session cookie may still be passed to a backend server. This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.

Severity
high
Software
Apache
Fixed in
2.4.69
Published
2026-10-01

Affected versions

From: 2.4.60

Until: 2.4.69

Fixed in: 2.4.69

How to fix this CVE

Update Apache HTTP Server to version 2.4.69 or later to remediate this session cookie disclosure vulnerability in mod_session_cookie. The vulnerability allows session cookies to leak to backend servers during internal redirects when SessionCookieRemove directives change between request processing stages. Administrators should prioritize this update to prevent unauthorized access to sensitive session data.

sudo dnf update httpd httpd-core httpd-modules httpd-tools

Defensia detects this vulnerability

How to check if you are affected

  1. Step 1: Check Apache version with 'apache2ctl -v' (Ubuntu/Debian) or 'httpd -v' (RHEL/CentOS/Amazon Linux) and confirm it is below 2.4.69
  2. Step 2: Verify if mod_session_cookie is loaded by running 'apache2ctl -M | grep session_cookie' (Ubuntu/Debian) or 'httpd -M | grep session_cookie' (RHEL/CentOS/Amazon Linux)
  3. Step 3: Search Apache access and error logs for internal redirect patterns (HTTP 3xx responses) combined with backend server requests: 'grep -E "(3[0-9]{2}|backend)" /var/log/apache2/access.log | head -50'
  4. Step 4: After patching, re-run 'apache2ctl -v' or 'httpd -v' to confirm version is 2.4.69 or later, then restart Apache with 'sudo systemctl restart apache2' (Ubuntu/Debian) or 'sudo systemctl restart httpd' (RHEL/CentOS/Amazon Linux)

FAQ

What is CVE-2026-47360?

CVE-2026-47360 is a session cookie exposure vulnerability in Apache's mod_session_cookie module where session cookies can be transmitted to backend servers during internal redirects if SessionCookieRemove directives are not consistently applied across redirect stages. This allows an attacker with access to backend logs or network traffic to potentially capture sensitive session identifiers.

Is CVE-2026-47360 being actively exploited?

No, CVE-2026-47360 is not currently listed on the CISA Known Exploited Vulnerabilities (KEV) catalog and no public exploits are available. However, the vulnerability should still be patched promptly as it involves direct exposure of sensitive session data.

What versions of Apache are affected by CVE-2026-47360?

Apache HTTP Server versions 2.4.0 through 2.4.68 are affected. The vulnerability is remediated in version 2.4.69 and later.

How do I check if my server is vulnerable to CVE-2026-47360?

Run 'apache2ctl -v' or 'httpd -v' and check the version number. If it reports a version between 2.4.0 and 2.4.68 inclusive, your server is vulnerable. Additionally confirm mod_session_cookie is active with 'apache2ctl -M | grep session_cookie'.

Does Defensia detect CVE-2026-47360?

Yes — Defensia's CVE advisory scanner compares installed package versions against the NVD database. If Apache is installed on a monitored server, CVE-2026-47360 will appear in your dashboard with remediation steps.

Related Apache CVEs

CVE-2024-38476CVSS 9.8Vulnerability in core of Apache HTTP Server 2.4.59 and earlier are vulnerably to information disclosure, SSRF or local script execution via backend applications whose response headers are malicious or exploitable. Users are recommended to upgrade to version 2.4.60, which fixes this issue.
CVE-2024-38474CVSS 9.8Substitution encoding issue in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows attacker to execute scripts in directories permitted by the configuration but not directly reachable by any URL or source disclosure of scripts meant to only to be executed as CGI. Users are recommended to upgrade to version 2.4.60, which fixes this issue. Some RewriteRules that capture and substitute unsafely will now fail unless rewrite flag "UnsafeAllow3F" is specified.
CVE-2026-28780CVSS 9.8Heap-based Buffer Overflow vulnerability in mod_proxy_ajp of Apache HTTP Server. If mod_proxy_ajp connects to a malicious AJP server this AJP server can send a malicious AJP message back to mod_proxy_ajp and cause it to write 4 attacker controlled bytes after the end of a heap based buffer. This issue affects Apache HTTP Server: through 2.4.66. Users are recommended to upgrade to version 2.4.67, which fixes the issue.
CVE-2025-23048CVSS 9.1In some mod_ssl configurations on Apache HTTP Server 2.4.35 through to 2.4.63, an access control bypass by trusted clients is possible using TLS 1.3 session resumption. Configurations are affected when mod_ssl is configured for multiple virtual hosts, with each restricted to a different set of trusted client certificates (for example with a different SSLCACertificateFile/Path setting). In such a case, a client trusted to access one virtual host may be able to access another virtual host, if SSLStrictSNIVHostCheck is not enabled in either virtual host.
CVE-2024-38475CVSS 9.1Improper escaping of output in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows an attacker to map URLs to filesystem locations that are permitted to be served by the server but are not intentionally/directly reachable by any URL, resulting in code execution or source code disclosure. Substitutions in server context that use a backreferences or variables as the first segment of the substitution are affected.  Some unsafe RewiteRules will be broken by this change and the rewrite flag "UnsafePrefixStat" can be used to opt back in once ensuring the substitution is appropriately constrained.

References

Track CVEs across your fleet automatically

Defensia scans your Linux servers and tells you exactly which ones are running vulnerable versions — including CVE-2026-47360. Free for 1 server.

Get started free