Sceawere
Vulnerability Detail
CVE-2026-58415UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Apache mod_dav_fs Information Disclosure
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 5.3
- Creation Date
- 1d ago
- Vendor
- Apache Software Foundation
- Product
- Apache HTTP Server
- Attack Type
- CWE-552 Files or directories accessible to external parties
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
Internal state files accessible to external parties in mod_dav_fs in Apache Software Foundation Apache HTTP Server before 2.4.69 on all platforms allows a remote client to read WebDAV dead properties of resources it cannot author via a GET request for the .DAV state directory This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "5.3",
"pubDate": "2026-10-01T17:17:29.260Z",
"pubdate": "2026-10-01T17:17:29.260Z",
"executiveSummary": "This vulnerability is an information disclosure flaw residing within the mod_dav_fs module of the Apache HTTP Server. It allows unauthorized remote clients to access and read internal state information associated with WebDAV resources.\nThe vulnerability stems from improper access control governing the .DAV state directory. Because the server fails to sufficiently restrict access to these internal filesystem objects, a remote attacker can retrieve sensitive WebDAV dead properties even for resources they lack the authorization to modify or author.\nAffected software includes Apache HTTP Server versions 2.4.0 through 2.4.68. This issue impacts all platforms where mod_dav_fs is enabled and configured.\nThe risk implication is significant as dead properties may contain metadata, versioning information, or other internal state details that were never intended for public exposure. Exploitation does not require elevated privileges or prior authentication, as the attack is initiated via a simple GET request. This vulnerability effectively bypasses established WebDAV access control policies by targeting the underlying implementation's metadata storage.",
"technicalDetails": "The root cause of this vulnerability lies in the improper handling of requests directed toward the .DAV state directory within the mod_dav_fs module of the Apache HTTP Server. In a standard WebDAV implementation, the mod_dav_fs module maintains metadata and 'dead properties'—custom properties not defined by the DAV specification—in a hidden directory structure typically prefixed with '.DAV'.\nUnder normal operating conditions, these directories are managed internally by the server to facilitate WebDAV transactions. However, due to a flaw in the request processing logic of mod_dav_fs, the server fails to verify if the requesting user possesses the necessary permissions to access these specific internal filesystem objects when a GET request is issued directly against the .DAV directory.\nThe exploitation flow is straightforward and does not require complex payloads. An attacker identifies a target Apache HTTP Server where the mod_dav_fs module is active. By crafting an HTTP GET request directed at the .DAV directory associated with a specific resource, the attacker triggers the module to serve the file content. Because the server logic incorrectly treats these requests as valid access attempts to static resources, it returns the requested dead properties in the HTTP response body.\nThis behavior exposes metadata that is meant to be private or confined to the administrative context of the WebDAV store. Since the vulnerability resides within the request handling of the module itself, it affects all platforms (e.g., Linux, Windows, macOS) where the software is deployed, provided the DAV provider is configured for filesystem storage. The attack is network-exposed, requiring only connectivity to the target web server. No authentication is necessary, meaning an unauthenticated remote actor can perform reconnaissance to enumerate resource properties, potentially revealing sensitive configuration details, file path structures, or information about user interactions that are stored as dead properties.\nThe vulnerability is present in Apache HTTP Server versions from 2.4.0 through 2.4.68. The absence of an access control check at the handler level for these specific paths allows the leakage to persist until the server is updated to version 2.4.69 or later, where the request handling for these internal directories is correctly constrained to prevent unauthorized reads."
}