Vulnerability Details CVE-2026-47360
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache HTTP Server's mod_session_cookie module.
When SessionCookieRemove changes across internal redirects, the session cookie may still be passed to a backend server.
This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.004
EPSS Ranking 30.3%
CVSS Severity
CVSS v3 Score 7.5
Products affected by CVE-2026-47360
-
cpe:2.3:a:apache:http_server:2.4.60
-
cpe:2.3:a:apache:http_server:2.4.61
-
cpe:2.3:a:apache:http_server:2.4.62
-
cpe:2.3:a:apache:http_server:2.4.63
-
cpe:2.3:a:apache:http_server:2.4.64
-
cpe:2.3:a:apache:http_server:2.4.65
-
cpe:2.3:a:apache:http_server:2.4.66
-
cpe:2.3:a:apache:http_server:2.4.67
-
cpe:2.3:a:apache:http_server:2.4.68