Hardcoded Configuration Path Vulnerability in Apache HTTP Server by Apache Lounge
CVE-2026-89281

Currently unrated

Key Information:

Vendor
CVE Published:
22 September 2026

What is CVE-2026-89281?

The Apache Lounge distribution of the Apache HTTP Server is susceptible to a hardcoded configuration path vulnerability in the openssl.cnf file. This flaw could enable local code execution, allowing attackers with access to the server to exploit this misconfiguration. Proper mitigation strategies should be adopted to prevent unauthorized access and enhance server security.

Affected Version(s)

Apache Lounge Windows 0

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.