Description
Improper Privilege Management vulnerability in Apache HTTP Server's mod_ssl via SSLRequire and file-related expressions.



This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.
Published: 2026-10-01
Score: 9.8 Critical
EPSS: n/a
KEV: No
Impact: Privilege Escalation
Action: Immediate Patch
AI Analysis

Impact

Apache HTTP Server’s mod_ssl contains an SSLRequire directive that can evaluate expressions against files. The vendor’s documentation reveals that the component incorrectly permits file‑related expression functions in the .htaccess context, allowing an attacker who can inject an expression to bypass authentication checks and obtain elevated privileges. This improper privilege management flaw may enable unauthorized code execution or access to protected resources on the server.

Affected Systems

The vulnerability exists in all releases of Apache HTTP Server from version 2.4.0 through 2.4.68, inclusive of all community and downstream distributions that have not upgraded. Any environment deploying these affected versions without mitigation remains susceptible.

Risk and Exploitability

The published CVSS score is 9.8 and the EPSS metric is unavailable, while the vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is a local or delegated write capability to the server’s configuration or .htaccess files, inferred from the requirement to inject a file‑related expression. Once such an expression is placed in a .htaccess file, the server will evaluate it as an SSLRequire rule, effectively granting the attacker privilege levels corresponding to the web server process. This can compromise confidentiality, integrity, and availability of the affected system.

Generated by OpenCVE AI on October 1, 2026 at 22:04 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Apache HTTP Server to a non‑affected release (2.4.69 or later).
  • Disable or remove the SSLRequire directive or any file‑related expressions from configuration files and .htaccess files.
  • Restrict file permissions on .htaccess and server configuration files so that only trusted administrators can modify them.

Generated by OpenCVE AI on October 1, 2026 at 22:04 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 21:30:00 +0000

Type Values Removed Values Added
References

Thu, 01 Oct 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 01 Oct 2026 20:00:00 +0000

Type Values Removed Values Added
First Time appeared Apache
Apache http Server
Vendors & Products Apache
Apache http Server

Thu, 01 Oct 2026 16:30:00 +0000

Type Values Removed Values Added
Description Improper Privilege Management vulnerability in Apache HTTP Server's mod_ssl via SSLRequire and file-related expressions. This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.
Title Apache HTTP Server: mod_ssl SSLRequire allows .htaccess ap_expr file-function
Weaknesses CWE-269
References

Subscriptions

Apache Http Server
cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-10-01T20:09:28.423Z

Reserved: 2026-07-07T11:36:12.629Z

Link: CVE-2026-59797

cve-icon Vulnrichment

Updated: 2026-10-01T20:09:28.423Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-10-01T17:17:29.527

Modified: 2026-10-01T21:17:23.263

Link: CVE-2026-59797

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T22:15:13Z

Weaknesses
  • CWE-269

    Improper Privilege Management