CVE-2026-59797·Apache vulnerability
Improper Privilege Management vulnerability in Apache HTTP Server's mod_ssl via SSLRequire and file-related expressions. This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.
- Severity
- critical
- Software
- Apache
- Fixed in
- 2.4.69
- Published
- 2026-10-01
Affected versions
From: 2.4.0
Until: 2.4.69
Fixed in: 2.4.69
How to fix this CVE
Upgrade Apache HTTP Server to version 2.4.69 or later to address a critical privilege escalation flaw in mod_ssl's SSLRequire and file-based expression handling. This vulnerability allows attackers to bypass authentication and authorization controls without credentials. Apply the patch immediately across all affected servers, as the flaw has a CVSS score of 9.8 and impacts confidentiality, integrity, and availability.
sudo dnf update httpd httpd-core httpd-modulesDefensia detects this vulnerability
How to check if you are affected
- Run 'apache2 -v' or 'httpd -v' and verify the version is 2.4.69 or later; versions 2.4.0 through 2.4.68 are vulnerable
- Check if mod_ssl is enabled with 'apache2ctl -M | grep ssl_module' or 'httpd -M | grep ssl_module'; if active and version is affected, the system is exposed
- Search Apache error and access logs for unusual authentication bypass patterns: grep -i 'SSLRequire\|mod_ssl' /var/log/apache2/error.log
- After patching, confirm the update with 'apache2 -v' and restart Apache with 'sudo systemctl restart apache2' to ensure the new version is running
FAQ
What is CVE-2026-59797?
This is a critical privilege escalation vulnerability in Apache mod_ssl that mishandles SSLRequire directives and file-based expressions, allowing attackers to bypass SSL certificate validation and authentication rules to gain unauthorized access.
Is CVE-2026-59797 being actively exploited?
According to CISA, CVE-2026-59797 is not currently listed in the Known Exploited Vulnerabilities catalog, and no public exploits have been released, though the severity warrants immediate patching.
What versions of Apache are affected by CVE-2026-59797?
Apache HTTP Server versions 2.4.0 through 2.4.68 are affected; version 2.4.69 and later contain the fix.
How do I check if my server is vulnerable to CVE-2026-59797?
Run 'apache2 -v' or 'httpd -v' and check the version number; if it shows 2.4.0 to 2.4.68, your server is vulnerable. Also confirm mod_ssl is loaded with 'apache2ctl -M | grep ssl_module'.
Does Defensia detect CVE-2026-59797?
Yes — Defensia's CVE advisory scanner compares installed package versions against the NVD database. If Apache is installed on a monitored server, CVE-2026-59797 will appear in your dashboard with remediation steps.
Related Apache CVEs
References
Track CVEs across your fleet automatically
Defensia scans your Linux servers and tells you exactly which ones are running vulnerable versions — including CVE-2026-59797. Free for 1 server.
Get started free