Status: UPDATED | Advisory ID: CVE-2026-73636
| CVE | CVE-2026-73636 |
| CVSS Score / Version | 8.1 (High) / CVSS v3.1 |
| Updated | 2026-10-01 |
| CVSS Vector | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H |
| CVSS Prose | attack vector is network; attack complexity is high; privileges required is none; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is high. |
| Affected products | Apache Software Foundation Apache HTTP Server |
| Classified as | CWE-294 (Authentication Bypass by Capture-replay) |
| Vendor | Product | Affected Versions | Patch Status |
|---|---|---|---|
| Apache Software Foundation | Apache HTTP Server |
| Subsystems | General OT |
| Sectors | Multiple |
Authentication bypass by capture-replay in mod_auth_digest in Apache Software Foundation Apache HTTP Server 2.4.x on all platforms allows a man-in-the-middle (MITM) attacker to replay captured digest authentication credentials via crafted requests that trigger garbage collection of the client's shared memory entry when AuthDigestNonceLifetime is set to 0.
Users are recommended to upgrade to version 2.4.69, which fixes this issue. (NVD)
Monitor Apache Software Foundation's web page for any future patch releases.
| Source | Reference |
|---|---|
| NVD | https://nvd.nist.gov/vuln/detail/CVE-2026-73636 |
| CVE | https://www.cve.org/CVERecord?id=CVE-2026-73636 |