PT-2026-97015 · Apache Lounge · Apache Http Server

CVE-2026-89282

·

Published

2026-09-22

·

Updated

2026-09-22

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Apache Lounge Windows distribution of Apache HTTP Server (affected versions not specified)
Description This issue involves insecure installation directory permissions within the default install directory on C:. The directory inherits write access for Authenticated Users, which could allow unauthorized modifications to the server files.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Incorrect Permission

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-89282

Affected Products

Apache Http Server