← Back to CVE List
CVE-2026-58415NVD
Vulnerability Summary
Internal state files accessible to external parties in mod_dav_fs in Apache Software Foundation Apache HTTP Server before 2.4.69 on all platforms allows a remote client to read WebDAV dead properties of resources it cannot author via a GET request for the .DAV state directory
This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.
This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.
CVSS v3.1 Base Metrics — Score 5.3 (MEDIUM)
Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredNone
User InteractionNone
ScopeUnchanged
ConfidentialityLow
IntegrityNone
AvailabilityNone
Affected & Patched Versions
- Apache Http Server >= 2.4.0 and < 2.4.69
- Apache Http Server 2.4.69