Improper Handler Deployment Flaw in Apache HTTP Server by Apache Software Foundation
CVE-2026-42356
3.7LOW
What is CVE-2026-42356?
A vulnerability in Apache HTTP Server allows an attacker to exploit the wrong handler deployment by utilizing certain internal redirects from CGI programs. If a target resides in a CGI-enabled directory and does not have an alternative MIME extension, it may be executed as a CGI script, leading to potential unauthorized access or execution of arbitrary commands.
Affected Version(s)
Apache HTTP Server 2.4.60 <= 2.4.68