{"id":"CVE-2026-89281","title":"The Apache Lounge Windows distribution of Apache HTTP Server build contains a hardcoded configuration path vulnerability within openssl.cnf path that can allow local code execution.","summary":"The Apache Lounge Windows distribution of Apache HTTP Server build contains a hardcoded configuration path vulnerability within openssl.cnf path that can allow local code execution.","severity":"none","cwe":["CWE-732"],"vendor":"Apache HTTP Server Project","product":"Apache Lounge Windows","affected":["apache_lounge_windows < Apache 2.4.68-260920 Win64"],"published":"2026-09-22","updated":"2026-09-22","sourceUpdated":"2026-09-22T20:17:11.380","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-89281","references":[{"url":"https://atos.net/en/lp/cybershield/a-tale-of-several-hijacks-and-what-it-taught-me-about-runtime-driven-testing","label":"cret@cert.org"},{"url":"https://httpd.apache.org/download.cgi","label":"cret@cert.org"},{"url":"https://www.apachelounge.com/viewtopic.php?t=9515","label":"cret@cert.org"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-09-22T20:10:15.102Z","slug":"CVE-2026-89281","body":"## Overview\n\nThe Apache Lounge Windows distribution of Apache HTTP Server build contains a hardcoded configuration path vulnerability within openssl.cnf path that can allow local code execution.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}