Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.5
CVE-2026-65639: ConfigServer Security & Firewall lets attacker run commands as root
CVE-2026-65639 · published 1 month ago
Summary
Both the original ConfigServer Security & Firewall and the WebPros-maintained version can let a remote attacker who controls an allow/deny feed run any command with full system privileges. This happens because the software does not properly check the data it receives from the feed. Update to version 16.30 (or later) and review any other custom forks for the same issue.
What to do
- Update webpros configserver security & firewall to version 16.30 or later.
- Update configserver configserver security & firewall to version * or later.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| webpros | configserver security & firewall | < 16.30 |
| configserver | configserver security & firewall | < * |
Original advisory text
OS command injection in the advanced-rule parser of ConfigServer Security & Firewall allows a remote attacker who controls a configured allow/deny feed to execute arbitrary commands as root, due to...
OS command injection in the advanced-rule parser of ConfigServer Security & Firewall allows a remote attacker who controls a configured allow/deny feed to execute arbitrary commands as root, due to insufficient validation of feed-supplied rule data.
The vulnerability affects versions of the software originally distributed by ConfigServer, as well as versions of the WebPros-maintained fork that contain the vulnerable code. WebPros has addressed the vulnerability in version 16.30. Other forks or independently maintained versions of ConfigServer Security & Firewall (CSF) may also be affected and should be evaluated independently.
The vulnerability affects versions of the software originally distributed by ConfigServer, as well as versions of the WebPros-maintained fork that contain the vulnerable code. WebPros has addressed the vulnerability in version 16.30. Other forks or independently maintained versions of ConfigServer Security & Firewall (CSF) may also be affected and should be evaluated independently.
Internet-facing
14 days
Internal
At next upgrade
- Not known to be exploited
- Needs hands-on effort to exploit
- Gives an attacker full control
Severity
9.5
Critical
Type
CWE-78OS Command Injection
Timeline
Published10 Sep 2026
Updated7 Oct 2026
First seen10 Sep 2026
Track software like this
Free during beta