{"id":"CVE-2026-89282","published":"2026-09-22T20:17:11.500","lastModified":"2026-09-23T17:58:00.627","description":"The Apache Lounge Windows distribution of Apache HTTP Server build contains an insecure installation directory permissions vulnerability through its default install directory on C:\\, which inherits write access for Authenticated Users.","cvssScore":9.1,"cvssSeverity":"CRITICAL","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","cwes":["CWE-732"],"vendors":[],"products":[],"references":[{"url":"https://atos.net/en/lp/cybershield/a-tale-of-several-hijacks-and-what-it-taught-me-about-runtime-driven-testing","tags":[]},{"url":"https://httpd.apache.org/download.cgi","tags":[]},{"url":"https://www.apachelounge.com/viewtopic.php?t=9515","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":{"summary":"The flaw allows authenticated users to write to the default install directory, posing a risk of unauthorized code execution or data modification.","exploitability":"Exploitation is relatively easy given write access for Authenticated Users, but requires initial authentication to the server.","blast_radius":"If exploited, it could lead to unauthorized changes or execution of malicious code on the server.","remediation":"Disable write access for Authenticated Users on the default install directory C:\\ or restrict access to authorized personnel only.","detection":"No reliable host or network indicator is derivable from the published description.","tags":["auth-bypass","write-access","web"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-28T08:51:40.589Z"}}