Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.

Apache HTTP Server: Insecure Direct Object Reference Vulnerability

CVE-2025-24321
Summary

Apache HTTP Server has an insecure direct object reference issue that can lead to unauthorized access to sensitive data. This means an attacker can potentially access restricted files or directories on a server. Update to the latest version of Apache HTTP Server to fix this issue and prevent unauthorized access.

Original title
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused
Original description
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused
Published: 13 Feb 2026 · Updated: 10 Mar 2026 · First seen: 6 Mar 2026