Status: UPDATED | Advisory ID: CVE-2026-48005
| CVE | CVE-2026-48005 |
| CVSS Score / Version | 7.5 (High) / CVSS v3.1 |
| Updated | 2026-10-02 |
| CVSS Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
| CVSS Prose | attack vector is network; attack complexity is low; privileges required is none; user interaction is none; scope is unchanged; confidentiality impact is none; integrity impact is none; availability impact is high. |
| Affected products | Apache Software Foundation Apache HTTP Server and Apache http_server |
| Classified as | CWE-306 (Missing Authentication for Critical Function) |
| Vendor | Product | Affected Versions | Patch Status |
|---|---|---|---|
| Apache Software Foundation | Apache HTTP Server | ||
| Apache | http_server |
| Subsystems | General OT |
| Sectors | Multiple |
Missing authentication checks in mod_auth_digest in Apache Software Foundation Apache HTTP Server before 2.4.69 on all platforms allows an unauthenticated remote client to cause a denial of service (forced re-authentication) via forged Authorization headers when Digest authentication is enabled with AuthDigestNcCheck .
Users are recommended to upgrade to version 2.4.69, which fixes this issue. (NVD)
Monitor Apache Software Foundation's and Apache's web pages for any future patch releases. See vendor advisory link below.
| Source | Reference |
|---|---|
| NVD | https://nvd.nist.gov/vuln/detail/CVE-2026-48005 |
| CVE | https://www.cve.org/CVERecord?id=CVE-2026-48005 |
| Vendor advisory | https://httpd.apache.org/security/vulnerabilities_24.html |