OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-89282

CRITICAL · CVSS 9.1 EPSS 0.27%

Source: NVD + CISA KEV + EPSS · Published 2026-09-22 · Last synced 2026-10-07

CyberRota Analysis

AI-Generated

The Apache Lounge Windows distribution of Apache HTTP Server is vulnerable due to insecure directory permissions in its default installation path on C:\, allowing Authenticated Users to gain write access. This could lead to unauthorized modifications or exploitation of the server environment, potentially compromising the integrity of hosted applications. Organizations using this distribution on Windows should prioritize addressing this vulnerability to mitigate risks associated with unauthorized access and data manipulation.

CVE
CVE-2026-89282
Severity
CRITICAL
CVSS
9.1
EPSS
0.27%
Windows Apache

Original NVD Description

The Apache Lounge Windows distribution of Apache HTTP Server build contains an insecure installation directory permissions vulnerability through its default install directory on C:\, which inherits write access for Authenticated Users.