mod_auth_openidc 2.4.19.4 Security Update: Patch CVE-2026-54789
August 21, 2026
Apache sites using mod_auth_openidc should update to version 2.4.19.4 or later. The maintainer’s security advisory says CVE-2026-54789 affects earlier releases and is fixed in 2.4.19.4. Treat this as a high-priority server-authentication maintenance task and use a controlled change process.
This guide is defensive by design. It focuses on identifying affected deployments, applying a supported update, and checking that protected applications still work normally. It does not include exploitation detail or diagnostic secrets.
Who Should Update
- Apache deployments running mod_auth_openidc before version 2.4.19.4.
- Teams that use the module to protect internal apps, customer portals, or administrative services with OpenID Connect.
- Managed hosting and platform teams maintaining more than one Apache node or tenant environment.
Plan the Update
- Inventory the installed module version on each Apache node through your normal server-management process.
- Schedule a maintenance window and follow the approved change, recovery, and communication process. Do not create or alter a backup schedule solely for this update.
- For load-balanced services, drain or place one node into maintenance at a time so healthy nodes continue serving protected applications.
- Use the supported operating-system or vendor package that provides mod_auth_openidc 2.4.19.4 or later. Review distribution compatibility before choosing a newer upstream release; the current upstream release list includes 2.4.20.2.
- Return each node to service only after its normal health checks pass, then continue through the remaining nodes.
Verify Authentication After Maintenance
- Confirm the installed module version is 2.4.19.4 or later on every updated node.
- Test a representative protected application with an approved test account, including normal sign-in, sign-out, and return to the application.
- Confirm ordinary single sign-on access and identity-provider returns behave as expected for the services in scope.
- Review normal service monitoring and authentication error telemetry for unexpected access failures, then handle validated findings through the established support process.
If You Cannot Update Immediately
Limit administrative access to approved users, reduce unnecessary exposure of protected services where your operating model permits it, and schedule supported maintenance as soon as practical. Temporary restrictions are not a replacement for the corrected release.
Related FixItPhill Guidance
Use the FixItPhill WordPress support hub for practical site-maintenance help and the security archive for current defensive update guidance.

