← All Advisories

CVE-2026-89282

Last refreshed2026-10-03

Status: UPDATED  |  Advisory ID: CVE-2026-89282

Key Details

CVECVE-2026-89282
CVSS Score / Version9.1 (Critical) / CVSS v3.1
Updated2026-09-23
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
CVSS Proseattack vector is network; attack complexity is low; privileges required is none; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is none.
Affected productsApache HTTP Server Project Apache Lounge Windows
Classified asCWE-732 (Incorrect Permission Assignment for Critical Resource)

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
Apache HTTP Server ProjectApache Lounge Windows
SubsystemsGeneral OT
SectorsMultiple

What to Know

The Apache Lounge Windows distribution of Apache HTTP Server build contains an insecure installation directory permissions vulnerability through its default install directory on C:\, which inherits write access for Authenticated Users.

What to Do

Monitor Apache HTTP Server Project's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-89282
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-89282