Improper Privilege Management in Apache HTTP Server's mod_ssl
CVE-2026-59797

Currently unrated

Key Information:

Vendor

Apache

Vendor
CVE Published:
1 October 2026

What is CVE-2026-59797?

An improper privilege management vulnerability has been identified in the mod_ssl module of the Apache HTTP Server. This issue arises from incorrect handling of SSLRequire directives and file-related expressions, allowing for potential unauthorized access. The vulnerability affects multiple versions of Apache HTTP Server from 2.4.0 to 2.4.68. Users are advised to implement mitigation measures as outlined in the vendor's security advisory.

Affected Version(s)

Apache HTTP Server 2.4.0 <= 2.4.68

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

kimchunbok
l1nx1n
Juthawong Naisanguansee
Charles Vosburgh
Mike Read
Ryoma Nishioka
.