OCTOBER 5, 2026
Live Feed
Back to database
Case File

CVE-2026-93546

HIGH · CVSS 8.8 EPSS 0.34%

Source: NVD + CISA KEV + EPSS · Published 2026-10-01 · Last synced 2026-10-05

CyberRota Analysis

AI-Generated

Apache HTTP Server versions up to 2.4.68 are vulnerable due to an integer overflow in the mod_dav_fs module, which can be exploited by authenticated WebDAV clients with write access. This vulnerability allows attackers to crash worker processes and corrupt a directory's property database through specially crafted PROPPATCH requests. Organizations using affected versions of Apache should prioritize patching to mitigate potential service disruptions and data integrity issues.

CVE
CVE-2026-93546
Severity
HIGH
CVSS
8.8
EPSS
0.34%
Apache

Original NVD Description

Integer overflow in mod_dav_fs in Apache HTTP Server through 2.4.68 allows an authenticated WebDAV client with write access to crash worker processes and persistently corrupt a directory's property database via PROPPATCH requests declaring many XML namespaces.

Related CVEs

Other vulnerabilities affecting the same vendor(s)