CVE-2026-47360·Apache vulnerability
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache HTTP Server's mod_session_cookie module. When SessionCookieRemove changes across internal redirects, the session cookie may still be passed to a backend server. This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.
- Severity
- high
- Software
- Apache
- Fixed in
- 2.4.69
- Published
- 2026-10-01
Affected versions
From: 2.4.60
Until: 2.4.69
Fixed in: 2.4.69
How to fix this CVE
Update Apache HTTP Server to version 2.4.69 or later to remediate this session cookie disclosure vulnerability in mod_session_cookie. The vulnerability allows session cookies to leak to backend servers during internal redirects when SessionCookieRemove directives change between request processing stages. Administrators should prioritize this update to prevent unauthorized access to sensitive session data.
sudo dnf update httpd httpd-core httpd-modules httpd-toolsDefensia detects this vulnerability
How to check if you are affected
- Step 1: Check Apache version with 'apache2ctl -v' (Ubuntu/Debian) or 'httpd -v' (RHEL/CentOS/Amazon Linux) and confirm it is below 2.4.69
- Step 2: Verify if mod_session_cookie is loaded by running 'apache2ctl -M | grep session_cookie' (Ubuntu/Debian) or 'httpd -M | grep session_cookie' (RHEL/CentOS/Amazon Linux)
- Step 3: Search Apache access and error logs for internal redirect patterns (HTTP 3xx responses) combined with backend server requests: 'grep -E "(3[0-9]{2}|backend)" /var/log/apache2/access.log | head -50'
- Step 4: After patching, re-run 'apache2ctl -v' or 'httpd -v' to confirm version is 2.4.69 or later, then restart Apache with 'sudo systemctl restart apache2' (Ubuntu/Debian) or 'sudo systemctl restart httpd' (RHEL/CentOS/Amazon Linux)
FAQ
What is CVE-2026-47360?
CVE-2026-47360 is a session cookie exposure vulnerability in Apache's mod_session_cookie module where session cookies can be transmitted to backend servers during internal redirects if SessionCookieRemove directives are not consistently applied across redirect stages. This allows an attacker with access to backend logs or network traffic to potentially capture sensitive session identifiers.
Is CVE-2026-47360 being actively exploited?
No, CVE-2026-47360 is not currently listed on the CISA Known Exploited Vulnerabilities (KEV) catalog and no public exploits are available. However, the vulnerability should still be patched promptly as it involves direct exposure of sensitive session data.
What versions of Apache are affected by CVE-2026-47360?
Apache HTTP Server versions 2.4.0 through 2.4.68 are affected. The vulnerability is remediated in version 2.4.69 and later.
How do I check if my server is vulnerable to CVE-2026-47360?
Run 'apache2ctl -v' or 'httpd -v' and check the version number. If it reports a version between 2.4.0 and 2.4.68 inclusive, your server is vulnerable. Additionally confirm mod_session_cookie is active with 'apache2ctl -M | grep session_cookie'.
Does Defensia detect CVE-2026-47360?
Yes — Defensia's CVE advisory scanner compares installed package versions against the NVD database. If Apache is installed on a monitored server, CVE-2026-47360 will appear in your dashboard with remediation steps.
Related Apache CVEs
References
Track CVEs across your fleet automatically
Defensia scans your Linux servers and tells you exactly which ones are running vulnerable versions — including CVE-2026-47360. Free for 1 server.
Get started free