CVE-2026-93546·Apache vulnerability
Integer overflow in mod_dav_fs in Apache HTTP Server through 2.4.68 allows an authenticated WebDAV client with write access to crash worker processes and persistently corrupt a directory's property database via PROPPATCH requests declaring many XML namespaces.
- Severity
- high
- Software
- Apache
- Fixed in
- 2.4.69
- Published
- 2026-10-01
Affected versions
Until: 2.4.69
Fixed in: 2.4.69
How to fix this CVE
Upgrade Apache HTTP Server to version 2.4.69 or later to patch an integer overflow vulnerability in the WebDAV module that can be triggered by authenticated users. Organizations running Apache 2.4.68 or earlier should prioritize this update, as the flaw allows crash and data corruption of property databases through specially crafted PROPPATCH requests. Apply the update during a maintenance window to ensure service continuity.
sudo dnf update httpdDefensia detects this vulnerability
WAF mitigation (if patching is not yet possible)
Add this rule to your WAF to block exploitation attempts while you schedule the patch.
Implement ModSecurity rules to block PROPPATCH requests containing excessive XML namespace declarations or restrict PROPPATCH method access to trusted internal sources onlyHow to check if you are affected
- Run 'apache2ctl -v' or 'httpd -v' to retrieve the currently installed Apache version and compare against 2.4.69
- Check if mod_dav and mod_dav_fs modules are enabled by running 'apache2ctl -M | grep dav' (Ubuntu/Debian) or 'httpd -M | grep dav' (RHEL/CentOS)
- Search Apache error and access logs for PROPPATCH requests with multiple XML namespace declarations using 'grep -i "PROPPATCH" /var/log/apache2/access.log' or equivalent log path
- Verify the patch was applied by running 'apache2ctl -v' or 'httpd -v' again and confirming the version is 2.4.69 or higher, then restart Apache with 'sudo systemctl restart apache2' or 'sudo systemctl restart httpd'
FAQ
What is CVE-2026-93546?
CVE-2026-93546 is an integer overflow flaw in Apache's WebDAV filesystem module that allows authenticated users with write permissions to send malformed property update requests, resulting in worker process crashes and corruption of directory metadata.
Is CVE-2026-93546 being actively exploited?
No, this vulnerability is not currently listed on CISA's Known Exploited Vulnerabilities catalog, and no public proof-of-concept exploits are available. However, the high CVSS score warrants timely remediation.
What versions of Apache are affected by CVE-2026-93546?
Apache HTTP Server versions up to and including 2.4.68 are vulnerable. The vulnerability is patched in version 2.4.69 and later.
How do I check if my server is vulnerable to CVE-2026-93546?
Run 'apache2ctl -v' (Debian/Ubuntu) or 'httpd -v' (RHEL/CentOS/Amazon Linux) and verify the version. If it is 2.4.68 or earlier and mod_dav is enabled ('apache2ctl -M | grep dav'), your server is vulnerable.
Does Defensia detect CVE-2026-93546?
Yes — Defensia's CVE advisory scanner compares installed package versions against the NVD database. If Apache is installed on a monitored server, CVE-2026-93546 will appear in your dashboard with remediation steps.
Related Apache CVEs
References
Track CVEs across your fleet automatically
Defensia scans your Linux servers and tells you exactly which ones are running vulnerable versions — including CVE-2026-93546. Free for 1 server.
Get started free