critical CVSS 9.8

CVE-2026-59797·Apache vulnerability

Improper Privilege Management vulnerability in Apache HTTP Server's mod_ssl via SSLRequire and file-related expressions. This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.

Severity
critical
Software
Apache
Fixed in
2.4.69
Published
2026-10-01

Affected versions

From: 2.4.0

Until: 2.4.69

Fixed in: 2.4.69

How to fix this CVE

Upgrade Apache HTTP Server to version 2.4.69 or later to address a critical privilege escalation flaw in mod_ssl's SSLRequire and file-based expression handling. This vulnerability allows attackers to bypass authentication and authorization controls without credentials. Apply the patch immediately across all affected servers, as the flaw has a CVSS score of 9.8 and impacts confidentiality, integrity, and availability.

sudo dnf update httpd httpd-core httpd-modules

Defensia detects this vulnerability

How to check if you are affected

  1. Run 'apache2 -v' or 'httpd -v' and verify the version is 2.4.69 or later; versions 2.4.0 through 2.4.68 are vulnerable
  2. Check if mod_ssl is enabled with 'apache2ctl -M | grep ssl_module' or 'httpd -M | grep ssl_module'; if active and version is affected, the system is exposed
  3. Search Apache error and access logs for unusual authentication bypass patterns: grep -i 'SSLRequire\|mod_ssl' /var/log/apache2/error.log
  4. After patching, confirm the update with 'apache2 -v' and restart Apache with 'sudo systemctl restart apache2' to ensure the new version is running

FAQ

What is CVE-2026-59797?

This is a critical privilege escalation vulnerability in Apache mod_ssl that mishandles SSLRequire directives and file-based expressions, allowing attackers to bypass SSL certificate validation and authentication rules to gain unauthorized access.

Is CVE-2026-59797 being actively exploited?

According to CISA, CVE-2026-59797 is not currently listed in the Known Exploited Vulnerabilities catalog, and no public exploits have been released, though the severity warrants immediate patching.

What versions of Apache are affected by CVE-2026-59797?

Apache HTTP Server versions 2.4.0 through 2.4.68 are affected; version 2.4.69 and later contain the fix.

How do I check if my server is vulnerable to CVE-2026-59797?

Run 'apache2 -v' or 'httpd -v' and check the version number; if it shows 2.4.0 to 2.4.68, your server is vulnerable. Also confirm mod_ssl is loaded with 'apache2ctl -M | grep ssl_module'.

Does Defensia detect CVE-2026-59797?

Yes — Defensia's CVE advisory scanner compares installed package versions against the NVD database. If Apache is installed on a monitored server, CVE-2026-59797 will appear in your dashboard with remediation steps.

Related Apache CVEs

CVE-2021-41773CVSS 10A flaw was found in a change made to path normalization in Apache HTTP Server 2.4.49. An attacker could use a path traversal attack to map URLs to files outside the directories configured by Alias-like directives. If files outside of these directories are not protected by the usual default configuration "require all denied", these requests can succeed. If CGI scripts are also enabled for these aliased pathes, this could allow for remote code execution. This issue is known to be exploited in the wild. This issue only affects Apache 2.4.49 and not earlier versions. The fix in Apache HTTP Server 2.4.50 was found to be incomplete, see CVE-2021-42013.
CVE-2021-42013CVSS 10It was found that the fix for CVE-2021-41773 in Apache HTTP Server 2.4.50 was insufficient. An attacker could use a path traversal attack to map URLs to files outside the directories configured by Alias-like directives. If files outside of these directories are not protected by the usual default configuration "require all denied", these requests can succeed. If CGI scripts are also enabled for these aliased pathes, this could allow for remote code execution. This issue only affects Apache 2.4.49 and Apache 2.4.50 and not earlier versions.
CVE-2024-38476CVSS 9.8Vulnerability in core of Apache HTTP Server 2.4.59 and earlier are vulnerably to information disclosure, SSRF or local script execution via backend applications whose response headers are malicious or exploitable. Users are recommended to upgrade to version 2.4.60, which fixes this issue.
CVE-2024-38474CVSS 9.8Substitution encoding issue in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows attacker to execute scripts in directories permitted by the configuration but not directly reachable by any URL or source disclosure of scripts meant to only to be executed as CGI. Users are recommended to upgrade to version 2.4.60, which fixes this issue. Some RewriteRules that capture and substitute unsafely will now fail unless rewrite flag "UnsafeAllow3F" is specified.
CVE-2026-56154CVSS 9.8Use After Free vulnerability in Apache HTTP Server's mod_rewrite when using lookahead (%{LA-U:HTTP:...}) This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.

References

Track CVEs across your fleet automatically

Defensia scans your Linux servers and tells you exactly which ones are running vulnerable versions — including CVE-2026-59797. Free for 1 server.

Get started free