Sceawere

Vulnerability Detail

CVE-2026-73636UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Apache mod_auth_digest Authentication Bypass

Vulnerability Metadata

Severity
High
Score / CVSS
8.1
Creation Date
1d ago
Vendor
Apache Software Foundation
Product
Apache HTTP Server
Attack Type
CWE-294 Authentication Bypass by Capture-replay
Vector String
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
HIGH

Narrative and Response

Description

Authentication bypass by capture-replay in mod_auth_digest in Apache Software Foundation Apache HTTP Server 2.4.x on all platforms allows a man-in-the-middle (MITM) attacker to replay captured digest authentication credentials via crafted requests that trigger garbage collection of the client's shared memory entry when AuthDigestNonceLifetime is set to 0. Users are recommended to upgrade to version 2.4.69, which fixes this issue.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "8.1",
  "pubDate": "2026-10-01T17:17:30.873Z",
  "pubdate": "2026-10-01T17:17:30.873Z",
  "executiveSummary": "The Apache HTTP Server mod_auth_digest module is vulnerable to an authentication bypass via a capture-replay attack. This vulnerability affects all Apache HTTP Server 2.4.x versions where the AuthDigestNonceLifetime configuration directive is explicitly set to 0. The issue arises from flawed logic within the shared memory management for digest authentication nonces, which allows a man-in-the-middle (MITM) attacker to intercept and subsequently replay captured digest authentication credentials. By sending specifically crafted requests that force the garbage collection of a client's shared memory entry, an attacker can bypass the intended expiration mechanisms of the digest authentication flow. Successful exploitation results in unauthorized access to restricted resources, potentially leading to a complete compromise of the authentication process for target sessions. This vulnerability poses a significant risk to confidentiality and integrity in environments utilizing digest authentication over insecure network channels, as it grants attackers the ability to masquerade as legitimate users without knowledge of the actual credentials, provided they can perform traffic interception and manipulation.",
  "technicalDetails": "The vulnerability is rooted in the implementation of the mod_auth_digest module within the Apache HTTP Server. Digest authentication relies on nonces to prevent replay attacks; these nonces are typically stored in shared memory for validation across subsequent requests. When the directive AuthDigestNonceLifetime is configured to 0, the intended behavior is to invalidate nonces immediately or treat them as single-use entities. However, the internal logic governing the lifecycle of these nonces within the shared memory segment fails to account for race conditions or manual trigger states when garbage collection processes are invoked.\nThe attack flow begins with a MITM position, where the attacker intercepts a valid digest authentication header from a legitimate client. The attacker then prepares a crafted malicious request designed to target the shared memory management subsystem. By triggering the garbage collection routine for the specific shared memory entry associated with the captured nonce, the attacker exploits a window of vulnerability where the state of the authentication session becomes inconsistent. The system, having prematurely cleared the entry associated with the nonce, may fail to properly validate the uniqueness or the status of the replayed credential, effectively permitting the re-authentication using the intercepted data.\nSpecifically, the vulnerability allows the reuse of authentication credentials that should have been invalidated. The garbage collection mechanism, when improperly handled under the AuthDigestNonceLifetime 0 condition, clears the tracking entry for the nonce but fails to robustly enforce the invalidation of the credential in a way that prevents subsequent processing of a replayed request containing that same nonce. Consequently, the attacker transmits the captured credentials to the server, and the server, lacking the memory-resident history of the nonce due to the induced garbage collection, processes the credentials as legitimate. The affected component is the mod_auth_digest module, which handles the validation logic for incoming digest headers. This vulnerability is present across all 2.4.x releases of the Apache HTTP Server prior to the release of 2.4.69. The exploit requires network-level access to position as an intermediary between the client and the server and the ability to influence the server's internal memory state through crafted requests."
}
CVE-2026-73636: Apache mod_auth_digest Authentication Bypass (HIGH Severity, CVSS: 8.1) | Sceawere