Description
Deployment of wrong handler vulnerability in Apache HTTP Server allows the target of some internal redirects from CGI programs to also be treated as CGI and executed. The target must already be in a directory enabled for CGI and have no other extension understood by mod_mime.



This issue affects Apache HTTP Server: from 2.4.60 through 2.4.68.
Published: 2026-10-01
Score: 3.7 Low
EPSS: n/a
KEV: No
Impact: Limited Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

The vulnerability arises internal redirect to a file located inside a directory marked as executable by mod_cgi but the file lacks an extension treated as CGI by mod_mime. The server incorrectly processes this target as CGI and executes it, allowing an attacker to run arbitrary code. The flaw is a form of limited remote code execution, confined to internal redirects to files in CGI directories.

Affected Systems

Apache HTTP Server versions 2.4.60 through 2.4.68 are affected. No other Apache products or versions are listed.

Risk and Exploitability

The flaw is exploitable by an attacker who can control the arguments to a CGI program that performs an internal redirect. Because the target file must already exist in a CGI-enabled directory and have no mod_mime mapping, the attack surface is narrow but still permits arbitrary code execution. The CVSS score is not supplied, and EPSS data is unavailable, so the current exploitation likelihood cannot be quantified. The vulnerability is not listed in CISA KEV. The most likely attack vector is an internal redirect from a CGI script to a non-CGI file in a CGI directory.

Generated by OpenCVE AI on October 1, 2026 at 18:01 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Apache HTTP Server to version 2.4.69 or newer
  • Avoid internal redirects to files inside directories configured as CGI directories
  • If upgrading is not possible, restrict internal redirect target directories to non-CGI paths or disable CGI execution for those directories

Generated by OpenCVE AI on October 1, 2026 at 18:01 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 3.7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 01 Oct 2026 16:00:00 +0000

Type Values Removed Values Added
Description Deployment of wrong handler vulnerability in Apache HTTP Server allows the target of some internal redirects from CGI programs to also be treated as CGI and executed. The target must already be in a directory enabled for CGI and have no other extension understood by mod_mime. This issue affects Apache HTTP Server: from 2.4.60 through 2.4.68.
Title Apache HTTP Server: limited RCE for some internal redirects to non-CGI files in CGI directories
Weaknesses CWE-430
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-10-01T16:19:36.759Z

Reserved: 2026-04-26T14:13:01.898Z

Link: CVE-2026-42356

cve-icon Vulnrichment

Updated: 2026-10-01T16:17:24.783Z

cve-icon NVD

Status : Received

Published: 2026-10-01T16:17:43.790

Modified: 2026-10-01T17:17:24.363

Link: CVE-2026-42356

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T18:15:10Z

Weaknesses
  • CWE-430

    Deployment of Wrong Handler