CVE-2026-89281

Summary

The Apache Lounge Windows distribution of Apache HTTP Server build contains a hardcoded configuration path vulnerability within openssl.cnf path that can allow local code execution.

Affected Software

VendorProductVersion RangeStatus
Apache HTTP Server ProjectApache Lounge Windows0 < Apache 2.4.68-260920 Win64affected

Weaknesses

  • CWE-732 Incorrect Permission Assignment for Critical Resource

References