• PATCH AVAILABLE

CVE-2026-89282: insecure permissions in Apache HTTP Server Project Apache Lounge Windows

Authenticated users can write to the default Apache Lounge Windows installation directory, allowing modification of server files and configuration on affected installs; tracked as CVE-2026-89282. The flaw affects the Apache Lounge Windows distribution before Apache 2.4.68-260920 Win64. An attacker needs an authenticated account on the host (a member of the Windows Authenticated Users group) to exploit the improper access control on the C:\ install directory.

Published Updated Source: CVE Program, NVD, FIRST EPSS

CVSS 3.1
9.1CRITICAL
EPSS
0.00268
CWE
CWE-732
KEV DUE DATE
Not listed
PATCH
Available

DIRAS TAKE

Urgent: install the fixed Apache 2.4.68-260920 Win64 build or correct NTFS permissions immediately because the default C:\ install directory grants write access to Authenticated Users.

What is CVE-2026-89282?

Authenticated users can write to the default Apache Lounge Windows installation directory, allowing modification of server files and configuration on affected installs; tracked as CVE-2026-89282. The flaw affects the Apache Lounge Windows distribution before Apache 2.4.68-260920 Win64. An attacker needs an authenticated account on the host (a member of the Windows Authenticated Users group) to exploit the improper access control on the C:\ install directory.

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Which versions of Apache HTTP Server Project Apache Lounge Windows are affected?

BRANCHAFFECTEDFIXED
Apache Lounge Windowsbefore Apache 2.4.68-260920 Win64Apache 2.4.68-260920 Win64

Is CVE-2026-89282 being exploited?

There are no public reports of exploitation as of 2026-09-30.

How to fix CVE-2026-89282

  1. Upgrade Apache Lounge Windows to Apache 2.4.68-260920 Win64.
  2. Restrict NTFS permissions on the installation directory so Authenticated Users do not have write access.
  3. Monitor webserver files and configuration for unexpected changes and enable file integrity checks.
  4. Follow the vendor guidance for secure installation and configuration of Apache Lounge Windows.

Frequently asked questions

Is CVE-2026-89282 being actively exploited?

There are no public reports of exploitation as of 2026-09-30.

Which Apache Lounge Windows versions are affected by CVE-2026-89282?

The vulnerability affects Apache Lounge Windows builds before Apache 2.4.68-260920 Win64.

Is there a patch for CVE-2026-89282?

Yes. The issue is fixed in Apache 2.4.68-260920 Win64; upgrade to that build to remediate the vulnerability.

Does CVE-2026-89282 require authentication?

Yes. Exploitation requires an authenticated account on the affected host (the default install grants write access to Authenticated Users).

References