CVE-2026-65638: OS Command Injection

Published Sep 10, 2026
·
Updated

Improper escaping of a request URL in ConfigServer Security & Firewall allows an unauthenticated remote attacker to execute arbitrary commands as the CSF service account via shell command injection.

The vulnerability affects versions of the software originally distributed by ConfigServer, as well as versions of the WebPros-maintained fork that contain the vulnerable code. WebPros has addressed the vulnerability in version 16.30. Other forks or independently maintained versions of ConfigServer Security & Firewall (CSF) may also be affected and should be evaluated independently.

Affected Software

2 affected components
ConfigServer ConfigServer Security & Firewall (CSF)
WebPros-maintained fork of ConfigServer Security & Firewall (CSF)<16.30

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade ConfigServer Security & Firewall (CSF) WebPros-maintained fork to a version that resolves this vulnerability.

    Fixed in 16.30

Event History

Sep 10, 2026
CVE Published
via MITRE·04:24 PM
Data Sourced
via MITRE·04:24 PM
DescriptionWeakness

Frequently Asked Questions

1

Who can exploit this issue, and what level of access is required?

An unauthenticated remote attacker can exploit the flaw. Successful exploitation allows arbitrary commands to run as the CSF service account.

2

Which deployments have a confirmed fix?

WebPros addressed the issue in version 16.30 of its maintained CSF fork. Versions originally distributed by ConfigServer and other independently maintained forks may be affected if they contain the vulnerable code and should be evaluated separately.

3

What should organizations check if they use a non-WebPros CSF build?

Determine whether the build contains the vulnerable request-URL escaping code. The available information does not identify fixed versions for ConfigServer-distributed releases or other forks.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203