CVE-2026-42356
Received Received - Intake

CGI Script Misexecution in Apache HTTP Server

Vulnerability report for CVE-2026-42356, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-01

Last updated on: 2026-10-01

Assigner: Apache Software Foundation

Description

Deployment of wrong handler vulnerability in Apache HTTP Server allows the target of some internal redirects from CGI programs to also be treated as CGI and executed. The target must already be in a directory enabled for CGI and have no other extension understood by mod_mime. This issue affects Apache HTTP Server: from 2.4.60 through 2.4.68.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-01
Last Modified
2026-10-01
Generated
2026-10-01
AI Q&A
2026-10-01
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
apache http_server From 2.4.60 (inc) to 2.4.68 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-430 The wrong "handler" is assigned to process an object.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in Apache HTTP Server allows internal redirects from CGI programs to incorrectly treat certain targets as CGI scripts and execute them. The target must already be in a CGI-enabled directory and lack an extension recognized by mod_mime.

Detection Guidance

This vulnerability involves internal redirects from CGI programs being incorrectly treated as CGI. To detect it, check Apache server logs for unusual CGI execution patterns or redirects targeting CGI-enabled directories. Look for requests with paths that lack CGI extensions but are processed as CGI scripts.

Impact Analysis

An attacker could exploit this to execute unintended CGI scripts, potentially leading to unauthorized actions, data access, or system compromise if the server processes malicious requests.

Compliance Impact

This vulnerability could lead to unauthorized data access or execution, violating confidentiality and integrity requirements in GDPR and HIPAA. Non-compliance may result in legal penalties or data breach notifications.

Mitigation Strategies

Upgrade Apache HTTP Server to a version that is not affected by this vulnerability. The issue affects versions 2.4.60 through 2.4.68, so upgrading to a version beyond 2.4.68 is recommended.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-42356. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart