CVE-2026-58415
Description
AI Translation Available
Internal state files accessible to external parties in mod_dav_fs in Apache Software Foundation Apache HTTP Server before 2.4.69 on all platforms allows a remote client to read WebDAV dead properties of resources it cannot author via a GET request for the .DAV state directory
This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.
552
Files or Directories Accessible to External Parties
DraftCommon Consequences
Security Scopes Affected:
Confidentiality
Integrity
Potential Impacts:
Read Files Or Directories
Modify Files Or Directories
Applicable Platforms
Technologies:
Not Technology-Specific, Cloud Computing
https://httpd.apache.org/security/vulnerabilities_24.html