CVE-2026-65639 PUBLISHED

Assigner: hackerone
Reserved: 22.07.2026 Published: 10.09.2026 Updated: 10.09.2026

OS command injection in the advanced-rule parser of ConfigServer Security & Firewall allows a remote attacker who controls a configured allow/deny feed to execute arbitrary commands as root, due to insufficient validation of feed-supplied rule data.

The vulnerability affects versions of the software originally distributed by ConfigServer, as well as versions of the WebPros-maintained fork that contain the vulnerable code. WebPros has addressed the vulnerability in version 16.30. Other forks or independently maintained versions of ConfigServer Security & Firewall (CSF) may also be affected and should be evaluated independently.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
CVSS Score: 9.5

Product Status

Vendor WebPros
Product ConfigServer Security & Firewall
Versions Default: unaffected
  • affected from 2.15 to 16.30 (excl.)
Vendor ConfigServer
Product ConfigServer Security & Firewall
Versions Default: unaffected
  • affected from 2.15 to * (excl.)

References

Problem Types

  • CWE-78 OS Command Injection CWE