CVE-2026-89281
N/A
N/A
Summary
The Apache Lounge Windows distribution of Apache HTTP Server build contains a hardcoded configuration path vulnerability within openssl.cnf path that can allow local code execution.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Apache HTTP Server Project | Apache Lounge Windows | 0 < Apache 2.4.68-260920 Win64 | affected |
Weaknesses
- CWE-732 Incorrect Permission Assignment for Critical Resource
References
- https://httpd.apache.org/download.cgi
- https://atos.net/en/lp/cybershield/a-tale-of-several-hijacks-and-what-it-taught-me-about-runtime-driven-testing
- https://www.apachelounge.com/viewtopic.php?t=9515
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.