Critical Out-of-Bounds Vulnerability in Apache2 Mod Auth OpenID Connect

Critical Out-of-Bounds Vulnerability in Apache2 Mod Auth OpenID Connect

First seen 2 Sep 2026, 19:43 UTC Linuxsecurity 60.8

Article Content

Browse articles
ThreatCluster

A critical vulnerability (CVE-2026-54789) has been identified in the Apache2 Mod Auth OpenID Connect module, affecting SUSE Linux Enterprise Server and openSUSE systems. This vulnerability allows for out-of-bounds reads and writes in the state-cookie parser, potentially leading to unauthorized access or system crashes. The flaw has a CVSS score of 7.5, indicating high severity. Users are advised to apply the available patches immediately to mitigate risks. The vulnerability was published on August 21, 2026, and is now being actively addressed by system administrators. The recommended installation methods include using 'zypper patch' or YaST online_update for applying the updates. Affected systems include SUSE Linux Enterprise Server 12 SP5 LTSS and openSUSE Leap 16.0.

Key Points: • CVE-2026-54789 affects Apache2 Mod Auth OpenID Connect with a CVSS score of 7.5. • Out-of-bounds read and write vulnerabilities can lead to unauthorized access. • Patches are available and should be applied immediately to affected systems.

Timeline

2026-08-21
CVE-2026-54789 published
A critical out-of-bounds vulnerability in Apache2 Mod Auth OpenID Connect was disclosed, affecting multiple SUSE and openSUSE systems.
Linuxsecurity
2026-09-01
Patch released for SUSE systems
SUSE released an important update to address CVE-2026-54789, urging users to apply the patch via recommended methods.
Linuxsecurity
2026-09-01
Patch released for openSUSE systems
openSUSE also issued a security update for the same vulnerability, advising users to patch their systems promptly.
Linuxsecurity