OCTOBER 3, 2026
Live Feed
Back to database
Case File

CVE-2026-47360

HIGH · CVSS 7.5 EPSS 0.28%

Source: NVD + CISA KEV + EPSS · Published 2026-10-01 · Last synced 2026-10-03

CyberRota Analysis

AI-Generated

The mod_session_cookie module in Apache HTTP Server versions 2.4.0 to 2.4.68 is vulnerable to an exposure of sensitive information, where session cookies may be inadvertently passed to backend servers during internal redirects. This could allow unauthorized actors to access sensitive session data, potentially leading to session hijacking or other malicious activities. Organizations using affected versions of Apache HTTP Server should prioritize patching to mitigate the risk of data exposure.

CVE
CVE-2026-47360
Severity
HIGH
CVSS
7.5
EPSS
0.28%
Apache

Original NVD Description

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache HTTP Server's mod_session_cookie module.   When SessionCookieRemove changes across internal redirects, the session cookie may still be passed to a backend server. This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.

Related CVEs

Other vulnerabilities affecting the same vendor(s)