Skip to main content
Apache Path Traversal: CVE-2021-41773 to RCE operation cover
COMING SOONBeginner

Apache Path Traversal: CVE-2021-41773 to RCE

An Apache 2.4.49 web server at Kestrel Analytics is targeted via CVE-2021-41773. An attacker uses percent-encoded path traversal to read /etc/passwd, confirms mod_cgi is enabled, and escalates to remote code execution. Walk the access logs and firewall traffic step by step to trace the traversal, the RCE, and the webshell that was left behind.

25m
6 tasks
25 points
Free

Launches in 4 days

Aug 11, 2026

Tuesday, August 11, 2026 at 9:00 AM

Create your free account

Be ready the moment it drops, free.

Training Tools

SIEMFirewall

What you'll investigate

6 objectives unlock when this operation goes live.

1Brief: a dot that should not be there
2Spot the traversal request
3Trace who escalated to command execution
4Find the webshell that was planted
5Identify the service account that ran the shell
6Map the initial access to MITRE ATT&CK

Be first when it launches

Create your free account now. The moment this operation goes live on Aug 11, 2026, you can jump straight in — and you'll have the rest of the catalog to train on meanwhile.

Get Started Free