CVE-2026-59797 is a vulnerability in Apache HTTP Server
Published on October 1, 2026
Apache HTTP Server: mod_ssl SSLRequire allows .htaccess ap_expr file-function
Improper Privilege Management vulnerability in Apache HTTP Server's mod_ssl via SSLRequire and file-related expressions.
This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.
Timeline
reported
fixed in 2.4.x by r1938672 95 days later.
2.4.69 released
Weakness Type
Improper Privilege Management
The software does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
Products Associated with CVE-2026-59797
Want to know whenever a new CVE is published for Apache HTTP Server? stack.watch will email you.
Affected Versions
Apache Software Foundation Apache HTTP Server:- Version 2.4.0, <= 2.4.68 is affected.