← All Advisories

CVE-2026-89281

Last refreshed2026-10-03

Status: UPDATED  |  Advisory ID: CVE-2026-89281

Key Details

CVECVE-2026-89281
CVSS Score / Version8.4 (High) / CVSS v3.1
Updated2026-09-23
CVSS VectorCVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS Proseattack vector is local; attack complexity is low; privileges required is none; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is high.
Affected productsApache HTTP Server Project Apache Lounge Windows
Classified asCWE-732 (Incorrect Permission Assignment for Critical Resource)

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
Apache HTTP Server ProjectApache Lounge Windows
SubsystemsGeneral OT
SectorsMultiple

What to Know

The Apache Lounge Windows distribution of Apache HTTP Server build contains a hardcoded configuration path vulnerability within openssl.cnf path that can allow local code execution.

What to Do

Monitor Apache HTTP Server Project's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-89281
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-89281