Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.8

CVE-2026-59797: Apache HTTP Server mod_ssl may grant unauthorized access

CVE-2026-59797 · published 9 days ago
Summary

Versions 2.4.0 through 2.4.68 of Apache HTTP Server’s mod_ssl component can mishandle permission checks when using SSLRequire and certain file‑related expressions. This could allow an attacker to bypass access controls and read or modify files they should not reach. Upgrade to the latest Apache HTTP Server release or apply the security patch provided by your distribution to resolve the issue.

What to do
  • Update alpine apache2 to version 2.4.69-r0.
  • Update bellsoft apache2 to version 2.4.69-r0.
  • Update debian apache2 to version 2.4.69-1.
  • Update apache to version 2.4.69.
  • Update apache2 to version 2.4.67-1~deb13u3.aikido.6.
  • Update rootio-apache2 to version 2.4.67-1~deb13u3.aikido.6.
  • Update apache2 to version 2.4.68-1~deb13u1.aikido.7.
  • Update rootio-apache2 to version 2.4.68-1~deb13u1.aikido.7.
  • Update canonical apache2 to version 2.4.7-1ubuntu4.22+esm16.
  • Update canonical apache2 to version 2.4.18-2ubuntu3.17+esm21.
  • Update canonical apache2 to version 2.4.29-1ubuntu4.27+esm12.
  • Update canonical apache2 to version 2.4.41-4ubuntu3.23+esm8.
  • Update canonical apache2 to version 2.4.52-1ubuntu4.24.
  • Update canonical apache2 to version 2.4.58-1ubuntu8.16.
  • Update canonical apache2 to version 2.4.66-2ubuntu2.5.
  • Update apache2 to version 2.4.69-r0.
  • Update apache http_server to version 2.4.69 or later.
Affected software
Ecosystem VendorProductAffected versions
– apache software foundation apache http server <= 2.4.68
Debian:12 debian apache2 All versions
Ubuntu:Pro:14.04:LTS canonical apache2 < 2.4.7-1ubuntu4.22+esm16
Fix: upgrade to 2.4.7-1ubuntu4.22+esm16
Alpine:v3.21 alpine apache2 < 2.4.69-r0
Fix: upgrade to 2.4.69-r0
Alpaquita:23 bellsoft apache2 >= 2.4.54-r2, < 2.4.69-r0
Fix: upgrade to 2.4.69-r0
Alpaquita:25 bellsoft apache2 >= 2.4.63-r0, < 2.4.69-r0
Fix: upgrade to 2.4.69-r0
Alpaquita:stream bellsoft apache2 >= 2.4.56-r0, < 2.4.69-r0
Fix: upgrade to 2.4.69-r0
– apache http_server >= 2.4.0, < 2.4.69
cpe:2.3:a:apache:http_server:*:*:*:*:*:*:*:*
Debian:14 debian apache2 < 2.4.69-1
Fix: upgrade to 2.4.69-1
Bitnami – apache >= 2.4.0, < 2.4.69
Fix: upgrade to 2.4.69
Root:Debian:13 – apache2 < 2.4.67-1~deb13u3.aikido.6
< 2.4.68-1~deb13u1.aikido.7
Fix: upgrade to 2.4.67-1~deb13u3.aikido.6
Root:Debian:13 – rootio-apache2 < 2.4.67-1~deb13u3.aikido.6
< 2.4.68-1~deb13u1.aikido.7
Fix: upgrade to 2.4.67-1~deb13u3.aikido.6
Ubuntu:Pro:16.04:LTS canonical apache2 < 2.4.18-2ubuntu3.17+esm21
Fix: upgrade to 2.4.18-2ubuntu3.17+esm21
Ubuntu:Pro:18.04:LTS canonical apache2 < 2.4.29-1ubuntu4.27+esm12
Fix: upgrade to 2.4.29-1ubuntu4.27+esm12
Ubuntu:Pro:20.04:LTS canonical apache2 < 2.4.41-4ubuntu3.23+esm8
Fix: upgrade to 2.4.41-4ubuntu3.23+esm8
Ubuntu:22.04:LTS canonical apache2 < 2.4.52-1ubuntu4.24
Fix: upgrade to 2.4.52-1ubuntu4.24
Ubuntu:24.04:LTS canonical apache2 < 2.4.58-1ubuntu8.16
Fix: upgrade to 2.4.58-1ubuntu8.16
Ubuntu:26.04:LTS canonical apache2 < 2.4.66-2ubuntu2.5
Fix: upgrade to 2.4.66-2ubuntu2.5
Alpine:v3.21 – apache2 < 2.4.69-r0
Fix: upgrade to 2.4.69-r0
Original advisory text
BELL-CVE-2026-59797
Improper Privilege Management vulnerability in Apache HTTP Server's mod_ssl via SSLRequire and file-related expressions.



This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.
Fix within
Internet-facing 3 days
Internal 60 days
  • Not known to be exploited
  • Can be exploited automatically
  • Gives an attacker full control
Severity
9.8 Critical
Exploitation
<1% chance of attack within 30 days
Type
CWE-269Improper Privilege Management
Timeline
Published1 Oct 2026
Updated9 Oct 2026
First seen1 Oct 2026
Track software like this
Free during beta