Apache HTTP Server mod_userdir+suexec Bypass Vulnerability Allowing Unintended User ID Execution

Vulnerability

A vulnerability has been identified in Apache HTTP Server versions 2.4.7 prior to 2.4.65, allowing for a mod_userdir and suexec bypass. This issue arises from the AllowOverride FileInfo directive, which enables users to manipulate the RequestHeader directive in .htaccess files. By doing so, they can cause certain CGI scripts to execute under an unexpected user ID, potentially leading to unauthorized actions or access.

Impact

Exploitation of this vulnerability can cause some CGI scripts to run under an unexpected user ID, which could lead to unauthorized access or actions on behalf of that user.

Remediation

Users are advised to upgrade to Apache HTTP Server version 2.4.66, which addresses this vulnerability.

Added: Dec 5, 2025, 11:17 AM
Updated: Dec 5, 2025, 6:43 PM

Vulnerability Rating

Custom Algorithm
spread
9.4
impact
0.0
exploitability
5.4
remediation
7.7
relevance
1.2
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.