Actively Exploited in the Wild

This vulnerability is being actively exploited in the wild.

Apache HTTP Server Privilege Escalation Vulnerability in Child Processes

Vulnerability

A privilege escalation vulnerability has been identified in Apache HTTP Server versions 2.4.17 prior to 2.4.39. This issue occurs in the event, worker, or prefork Multi-Processing Modules (MPMs). The vulnerability allows code running in less-privileged child processes or threads, including those executing CGI scripts or using an in-process scripting interpreter, to execute arbitrary code with the privileges of the parent process, typically root. The exploitation is achieved by manipulating the scoreboard, which can lead to unauthorized access or modifications. Non-Unix systems are not affected.

Impact

Exploitation of this vulnerability could result in unauthorized execution of code with elevated privileges, potentially leading to a full system compromise.

Reproduction

The vulnerability can be reproduced by uploading a malicious CGI script to a server running an affected version of Apache HTTP Server with the event, worker, or prefork MPMs enabled. Once the script is executed, it can manipulate the scoreboard to escalate privileges and execute arbitrary code as the root user.

Remediation

Users are advised to upgrade to Apache HTTP Server version 2.4.39 or later. Red Hat JBoss Core Services Apache HTTP Server 2.4.29 SP2 also includes this fix.

Added: May 14, 2026, 6:22 AM
Updated: May 14, 2026, 6:22 AM

Vulnerability Rating

Custom Algorithm
spread
9.4
impact
10.0
exploitability
4.7
remediation
7.7
relevance
0.0
threat
9.3
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.