WebPros security advisory (AV26-908)
ConfigServer Security & Firewall has a flaw that lets an unauthenticated remote attacker execute arbitrary commands as the CSF service account.
- Severity
- CriticalCVSS 4.0 · 9.2
- Fix
- Fixed in 16.30
- Affected versions
- 14.00 to before 16.30; from 14.00
- Weakness
- CWE-78OS Command Injection
- Exploit likelihood
- 3.2% in 30 daysEPSS, higher than 87% of known flaws
- Affects
- ConfigServer Security & Firewall
- Exploited
- Not confirmedNo confirmation recorded
- CISA SSVC
- No known exploitationAutomatable: no · Technical impact: total
- EU ID
- EUVD-2026-75595ENISA vulnerability database
How it works
- The flaw is improper escaping of a request URL.
- An unauthenticated remote attacker can inject shell commands through that URL.
- CSF then executes arbitrary commands as its service account.
What to do
Check the installed CSF version and compare it with the advisory. WebPros-maintained versions below 16.30 are affected; originally ConfigServer-distributed versions from 14.00 onward are listed as affected.
Update the WebPros-maintained fork to version 16.30 or later. Evaluate original ConfigServer releases and other forks independently against the advisory.
Technical details
CVE-2026-65638 is an unauthenticated shell command injection flaw in ConfigServer Security & Firewall. WebPros addressed the vulnerable code in version 16.30, while the CVE record lists originally ConfigServer-distributed versions from 14.00 onward as affected.
Severity breakdown
- Attack vector Network Requires network access to the vulnerable service
- Attack complexity Low No extra steps to bypass built-in attack protections
- Required conditions Present Attack depends on particular deployment or execution conditions
- Privileges required None Attacker needs no account or login
- User action None No action by another user is required
- Vulnerable system: Data exposure High Sensitive data can be exposed with serious impact
- Vulnerable system: Data changes High Protected data can be changed with serious impact
- Vulnerable system: Service disruption High The service can stop or suffer serious disruption
- Other systems: Data exposure Low Some data can be read
- Other systems: Data changes Low Some data can be modified
- Other systems: Service disruption None No additional impact beyond the vulnerable system
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X Open in FIRST.org calculatorReferences
- cve.org · CVERecord vdb entry
- tenable.com · CVE-2026-65638 third party advisory vdb entry
- cvefeed.io · CVE-2026-65638 third party advisory vdb entry
- cveawg.mitre.org · CVE-2026-65638
- support.cpanel.net · 43387915588375-Security-CVE-2026-65638-CSF-Security-Release CCCS Canada
- support.cpanel.net · 43187903921559-Security-CVE-2026-67401-SQL-Injection-Vulnerability-in-cPanel-s-EmailTrack-Functionality-September-8-2026 CCCS Canada
- support.cpanel.net · 43387923160343-Security-CVE-2026-65639-CSF-Security-Release CCCS Canada
- support.cpanel.net · 360007088193-Security CCCS Canada
- securityonline.info · csf-plugin-vulnerabilities-cvss-9-5 SecurityOnline
- gbhackers.com · cpanel-urges-users-to-patch-configserver-firewall GBHackers
- cybersecuritynews.com · cpanel-configserver-security-firewall-vulnerability Cyber Security News