OCTOBER 5, 2026
Live Feed
Back to database
Case File

CVE-2026-73636

HIGH · CVSS 8.1 EPSS 0.37%

Source: NVD + CISA KEV + EPSS · Published 2026-10-01 · Last synced 2026-10-05

CyberRota Analysis

AI-Generated

The Apache HTTP Server 2.4.x is vulnerable to an authentication bypass due to a capture-replay flaw in the mod_auth_digest module, which allows a man-in-the-middle attacker to exploit captured digest credentials. This vulnerability can be triggered when the AuthDigestNonceLifetime is set to 0, enabling unauthorized access through crafted requests. Organizations using affected versions should prioritize upgrading to version 2.4.69 to mitigate this risk.

CVE
CVE-2026-73636
Severity
HIGH
CVSS
8.1
EPSS
0.37%
Apache

Original NVD Description

Authentication bypass by capture-replay in mod_auth_digest in Apache Software Foundation Apache HTTP Server 2.4.x on all platforms allows a man-in-the-middle (MITM) attacker to replay captured digest authentication credentials via crafted requests that trigger garbage collection of the client's shared memory entry when AuthDigestNonceLifetime is set to 0. Users are recommended to upgrade to version 2.4.69, which fixes this issue.

Related CVEs

Other vulnerabilities affecting the same vendor(s)