CVE-2026-89282: Apache Lounge Apache HTTP Server vulnerability
The Apache Lounge Windows distribution of Apache HTTP Server build contains an insecure installation directory permissions vulnerability through its default install directory on C:\, which inherits write access for Authenticated Users.
Affected Software
Event History
Frequently Asked Questions
Who is exposed to this issue?
Systems using the Apache Lounge Windows distribution of Apache HTTP Server installed in its default directory on C:\ are exposed, because that location inherits write access for Authenticated Users.
What access would an attacker need to exploit it?
An attacker would need to authenticate to the affected Windows system as a user covered by the Authenticated Users group and be able to write to the inherited-permissions installation directory.
Is a default installation affected?
Yes. The issue is specifically associated with the Apache Lounge build's default installation directory on C:\ and its inherited write permissions for Authenticated Users.