Sceawere
Vulnerability Detail
CVE-2026-48005UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Apache mod_auth_digest Authentication Bypass
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.5
- Creation Date
- 1d ago
- Vendor
- Apache Software Foundation
- Product
- Apache HTTP Server
- Attack Type
- CWE-306 Missing authentication for critical function
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
Missing authentication checks in mod_auth_digest in Apache Software Foundation Apache HTTP Server before 2.4.69 on all platforms allows an unauthenticated remote client to cause a denial of service (forced re-authentication) via forged Authorization headers when Digest authentication is enabled with AuthDigestNcCheck . Users are recommended to upgrade to version 2.4.69, which fixes this issue.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.5",
"pubDate": "2026-10-01T17:17:25.480Z",
"pubdate": "2026-10-01T17:17:25.480Z",
"executiveSummary": "A critical vulnerability exists in the Apache HTTP Server's mod_auth_digest module, specifically affecting configurations where AuthDigestNcCheck is enabled. This flaw stems from missing authentication checks, which permits unauthenticated remote attackers to trigger a denial of service (DoS) condition.\nThe vulnerability allows an attacker to force repeated re-authentication events by submitting forged Authorization headers. Because the server fails to properly validate the integrity of these headers under specific module configurations, the attacker can disrupt legitimate user access to protected resources. This vulnerability affects all platforms running Apache HTTP Server versions prior to 2.4.69.\nThe risk implication is significant for high-availability environments relying on Digest authentication, as it provides a mechanism for remote attackers to degrade service performance without requiring privileged access. Successful exploitation does not require prior authentication, making the service globally exposed if reachable via the network. Organizations should prioritize upgrading to version 2.4.69 to mitigate this risk.",
"technicalDetails": "The vulnerability resides within the mod_auth_digest module of the Apache HTTP Server. This module is responsible for handling Digest authentication, which is designed to provide a more secure alternative to Basic authentication by sending a hashed challenge-response rather than credentials in plaintext. The specific flaw is triggered when the AuthDigestNcCheck directive is enabled in the server configuration.\nThe AuthDigestNcCheck directive instructs the server to track the nonce count (NC) to prevent replay attacks. The root cause of the vulnerability is an inadequate validation mechanism within the logic processing the Authorization header. When an attacker sends a crafted request containing a forged or manipulated Authorization header, the server's mod_auth_digest component fails to verify the authenticity of the nonce count and the associated digest before accepting the request state.\nThe attack flow proceeds as follows: First, the attacker identifies a resource protected by Digest authentication where AuthDigestNcCheck is active. The attacker then constructs a malicious HTTP request featuring a forged Authorization header. Upon receiving this request, the server’s mod_auth_digest component processes the header. Due to the missing validation check, the server incorrectly interprets the malicious input as a valid authentication attempt or a state change. By repeatedly submitting these forged headers, the attacker can force the server to repeatedly invalidate existing sessions or force re-authentication cycles for valid users.\nThis behavior manifests as a Denial of Service (DoS) attack, as the server's resources are consumed by managing these illegitimate re-authentication requests, effectively preventing legitimate clients from maintaining persistent or authenticated sessions. The vulnerability is exploitable by an unauthenticated remote client, as the exploit relies on the initial, unauthenticated handshake phase of the Digest authentication protocol. No specific privileges are required, and the attack is limited only by network reachability to the vulnerable Apache HTTP Server instance. This vulnerability affects all Apache HTTP Server deployments version 2.4.68 and earlier. Post-exploitation, the server remains reachable but functionally impaired, leading to significant disruption of services requiring authenticated access."
}