Sceawere
Vulnerability Detail
CVE-2026-79768UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
mod_userdir Path Equivalence Vulnerability
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 5.3
- Creation Date
- 1d ago
- Vendor
- Apache Software Foundation
- Product
- Apache HTTP Server
- Attack Type
- CWE-55 Path equivalence: '/./' (single dot directory)
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
Path equivalence: '/./' (single dot directory) vulnerability in Apache HTTP Server's mod_userdir module when configured with absolute non-wildcard UserDir directive (the 2nd form in https://httpd.apache.org/docs/2.4/mod/mod_userdir.html#userdir) This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "5.3",
"pubDate": "2026-10-01T17:17:31.910Z",
"pubdate": "2026-10-01T17:17:31.910Z",
"executiveSummary": "A path equivalence vulnerability exists in the Apache HTTP Server mod_userdir module, specifically when the UserDir directive is configured using the absolute non-wildcard format.\nThe vulnerability allows for improper path normalization, where a single dot directory ('/./') within a request path is mishandled by the server.\nThis flaw impacts Apache HTTP Server versions 2.4.0 through 2.4.68. The vulnerability enables attackers to bypass intended access restrictions or directory path constraints by manipulating the request URL structure.\nThe security implications involve unauthorized access to files or directories outside of the intended user directory scope, potentially leading to information disclosure.\nThe attack is executed by crafting specific HTTP requests containing the dot-directory notation, which the server fails to resolve correctly against the absolute path defined in the configuration.\nExploitation does not inherently require authentication but is contingent upon the specific non-wildcard configuration of the mod_userdir module on the target system.",
"technicalDetails": "The vulnerability originates from how the mod_userdir module processes request paths when the UserDir directive is explicitly set to an absolute path (e.g., 'UserDir /var/www/html/users/').\nUnder these specific configuration parameters, the module fails to properly normalize URI segments containing '/./' before performing authorization and path mapping checks.\nIn standard filesystem and URL semantics, '/./' is treated as a self-referential directory (the current directory) and should be resolved away during the canonicalization phase. However, due to a flaw in the module's path handling logic, the server incorrectly validates or maps the request path when this specific segment is present.\nThe attack flow begins with an attacker crafting a request directed at a URI path managed by mod_userdir, inserting the '/./' segment into the URL. For example, a request to '/~user/./secret-file' might be processed incorrectly if the target directory is mapped via an absolute UserDir directive.\nBecause the module does not strip or resolve the '/./' correctly during the initial path mapping, the underlying Apache core or the module itself may inadvertently treat the path as a valid access request to a location that should have been restricted or protected under the module's normal path-translation rules.\nThis effectively constitutes a path traversal or path equivalence vulnerability where the server's perception of the requested path differs from the actual filesystem path, leading to potential access bypass.\nVulnerable component: Apache HTTP Server mod_userdir module.\nAffected versions: 2.4.0 through 2.4.68.\nExploitation requires that the server is configured with an absolute, non-wildcard path for UserDir. No authentication is typically required if the resource can be reached via the vulnerable module's path logic.\nThe post-exploitation impact primarily involves the exposure of sensitive files or directories that the attacker should not have been authorized to access, as the misinterpretation of the path allows for the circumvention of established access control lists (ACLs) or directory restrictions."
}