The CVE-2026-79768 notice describes a path-equivalence flaw in Apache HTTP Server’s mod_userdir module. Under a specific configuration, using “/./” (a single-dot directory) may lead to information disclosure.
The stated condition requires an absolute UserDir directive without a wildcard, identified in the notice as the second documented form of that directive. The notice rates the issue low severity. Affected versions are Apache HTTP Server 2.4.0 through 2.4.68.
The item was published on October 1, 2026 by Eric Covener in the oss-sec feed and is presented as an automated translation. For context and updates, consult the original post in the feed archive and Apache’s official documentation and advisories. Check whether your installation’s version and configuration match the stated conditions.
When using AI to study or apply the notice, avoid including internal configurations, credentials, or personal data unless necessary. If you use the Rota Nacional API, check your organization’s data policy before sending content; configured detection and handling take place before a model runs.