high CVSS 8.8

CVE-2026-93546·Apache vulnerability

Integer overflow in mod_dav_fs in Apache HTTP Server through 2.4.68 allows an authenticated WebDAV client with write access to crash worker processes and persistently corrupt a directory's property database via PROPPATCH requests declaring many XML namespaces.

Severity
high
Software
Apache
Fixed in
2.4.69
Published
2026-10-01

Affected versions

Until: 2.4.69

Fixed in: 2.4.69

How to fix this CVE

Upgrade Apache HTTP Server to version 2.4.69 or later to patch an integer overflow vulnerability in the WebDAV module that can be triggered by authenticated users. Organizations running Apache 2.4.68 or earlier should prioritize this update, as the flaw allows crash and data corruption of property databases through specially crafted PROPPATCH requests. Apply the update during a maintenance window to ensure service continuity.

sudo dnf update httpd

Defensia detects this vulnerability

WAF mitigation (if patching is not yet possible)

Add this rule to your WAF to block exploitation attempts while you schedule the patch.

Implement ModSecurity rules to block PROPPATCH requests containing excessive XML namespace declarations or restrict PROPPATCH method access to trusted internal sources only

How to check if you are affected

  1. Run 'apache2ctl -v' or 'httpd -v' to retrieve the currently installed Apache version and compare against 2.4.69
  2. Check if mod_dav and mod_dav_fs modules are enabled by running 'apache2ctl -M | grep dav' (Ubuntu/Debian) or 'httpd -M | grep dav' (RHEL/CentOS)
  3. Search Apache error and access logs for PROPPATCH requests with multiple XML namespace declarations using 'grep -i "PROPPATCH" /var/log/apache2/access.log' or equivalent log path
  4. Verify the patch was applied by running 'apache2ctl -v' or 'httpd -v' again and confirming the version is 2.4.69 or higher, then restart Apache with 'sudo systemctl restart apache2' or 'sudo systemctl restart httpd'

FAQ

What is CVE-2026-93546?

CVE-2026-93546 is an integer overflow flaw in Apache's WebDAV filesystem module that allows authenticated users with write permissions to send malformed property update requests, resulting in worker process crashes and corruption of directory metadata.

Is CVE-2026-93546 being actively exploited?

No, this vulnerability is not currently listed on CISA's Known Exploited Vulnerabilities catalog, and no public proof-of-concept exploits are available. However, the high CVSS score warrants timely remediation.

What versions of Apache are affected by CVE-2026-93546?

Apache HTTP Server versions up to and including 2.4.68 are vulnerable. The vulnerability is patched in version 2.4.69 and later.

How do I check if my server is vulnerable to CVE-2026-93546?

Run 'apache2ctl -v' (Debian/Ubuntu) or 'httpd -v' (RHEL/CentOS/Amazon Linux) and verify the version. If it is 2.4.68 or earlier and mod_dav is enabled ('apache2ctl -M | grep dav'), your server is vulnerable.

Does Defensia detect CVE-2026-93546?

Yes — Defensia's CVE advisory scanner compares installed package versions against the NVD database. If Apache is installed on a monitored server, CVE-2026-93546 will appear in your dashboard with remediation steps.

Related Apache CVEs

CVE-2021-41773CVSS 10A flaw was found in a change made to path normalization in Apache HTTP Server 2.4.49. An attacker could use a path traversal attack to map URLs to files outside the directories configured by Alias-like directives. If files outside of these directories are not protected by the usual default configuration "require all denied", these requests can succeed. If CGI scripts are also enabled for these aliased pathes, this could allow for remote code execution. This issue is known to be exploited in the wild. This issue only affects Apache 2.4.49 and not earlier versions. The fix in Apache HTTP Server 2.4.50 was found to be incomplete, see CVE-2021-42013.
CVE-2021-42013CVSS 10It was found that the fix for CVE-2021-41773 in Apache HTTP Server 2.4.50 was insufficient. An attacker could use a path traversal attack to map URLs to files outside the directories configured by Alias-like directives. If files outside of these directories are not protected by the usual default configuration "require all denied", these requests can succeed. If CGI scripts are also enabled for these aliased pathes, this could allow for remote code execution. This issue only affects Apache 2.4.49 and Apache 2.4.50 and not earlier versions.
CVE-2026-56154CVSS 9.8Use After Free vulnerability in Apache HTTP Server's mod_rewrite when using lookahead (%{LA-U:HTTP:...}) This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.
CVE-2026-59797CVSS 9.8Improper Privilege Management vulnerability in Apache HTTP Server's mod_ssl via SSLRequire and file-related expressions. This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.
CVE-2024-38476CVSS 9.8Vulnerability in core of Apache HTTP Server 2.4.59 and earlier are vulnerably to information disclosure, SSRF or local script execution via backend applications whose response headers are malicious or exploitable. Users are recommended to upgrade to version 2.4.60, which fixes this issue.

References

Track CVEs across your fleet automatically

Defensia scans your Linux servers and tells you exactly which ones are running vulnerable versions — including CVE-2026-93546. Free for 1 server.

Get started free