Skip to content
Rota Nacional

Cyber ·

Apache mod_dav_fs: flaw in PROPPATCH requests

A notice published on October 1, 2026 reports a moderate flaw in Apache HTTP Server through version 2.4.68. An authenticated WebDAV client with write access may cause service disruption and persistent data corruption.

The notice, published on October 1, 2026 and attributed to Eric Covener, describes CVE-2026-93546 in the Apache HTTP Server mod_dav_fs module. It rates the severity as moderate and lists versions through 2.4.68 as affected.

According to the report, an integer overflow may let an authenticated WebDAV client with write access crash worker processes and persistently corrupt a directory's properties database. The trigger is PROPPATCH requests declaring many XML namespaces.

To assess exposure, check which servers run Apache and identify their installed versions. Consult the original notice and the project's official guidance to confirm the scope and recommended measures; the supplied text does not specify a fixed version.

While investigating, review who has WebDAV write access, preserve backups, and monitor service availability and data integrity. If you use AI to examine configurations or reports, remove credentials and personal data before submitting content, and verify conclusions against official sources.

Get new articles

Privacy, AI engineering and security in your inbox.

Rota Nacional

Bring privacy into your workflow.

30 days, no card, with a starting quota. After that, Pix credit from R$ 5,00.

Try free