WebPros security advisory (AV26-908)

Published September 10, 2026 CVE-2026-65638

ConfigServer Security & Firewall has a flaw that lets an unauthenticated remote attacker execute arbitrary commands as the CSF service account.

Severity
CriticalCVSS 4.0 · 9.2
Fix
Fixed in 16.30
Affected versions
14.00 to before 16.30; from 14.00
Weakness
CWE-78OS Command Injection
Exploit likelihood
3.2% in 30 daysEPSS, higher than 87% of known flaws
Affects
ConfigServer Security & Firewall
Exploited
Not confirmedNo confirmation recorded
CISA SSVC
No known exploitationAutomatable: no · Technical impact: total
EU ID
EUVD-2026-75595ENISA vulnerability database

How it works

  • The flaw is improper escaping of a request URL.
  • An unauthenticated remote attacker can inject shell commands through that URL.
  • CSF then executes arbitrary commands as its service account.

What to do

Check the installed CSF version and compare it with the advisory. WebPros-maintained versions below 16.30 are affected; originally ConfigServer-distributed versions from 14.00 onward are listed as affected.

Update the WebPros-maintained fork to version 16.30 or later. Evaluate original ConfigServer releases and other forks independently against the advisory.

Technical details

CVE-2026-65638 is an unauthenticated shell command injection flaw in ConfigServer Security & Firewall. WebPros addressed the vulnerable code in version 16.30, while the CVE record lists originally ConfigServer-distributed versions from 14.00 onward as affected.

Severity breakdown

  • Attack vector Network Requires network access to the vulnerable service
  • Attack complexity Low No extra steps to bypass built-in attack protections
  • Required conditions Present Attack depends on particular deployment or execution conditions
  • Privileges required None Attacker needs no account or login
  • User action None No action by another user is required
  • Vulnerable system: Data exposure High Sensitive data can be exposed with serious impact
  • Vulnerable system: Data changes High Protected data can be changed with serious impact
  • Vulnerable system: Service disruption High The service can stop or suffer serious disruption
  • Other systems: Data exposure Low Some data can be read
  • Other systems: Data changes Low Some data can be modified
  • Other systems: Service disruption None No additional impact beyond the vulnerable system
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X Open in FIRST.org calculator