CVE-2026-65638: OS Command Injection
Improper escaping of a request URL in ConfigServer Security & Firewall allows an unauthenticated remote attacker to execute arbitrary commands as the CSF service account via shell command injection.
The vulnerability affects versions of the software originally distributed by ConfigServer, as well as versions of the WebPros-maintained fork that contain the vulnerable code. WebPros has addressed the vulnerability in version 16.30. Other forks or independently maintained versions of ConfigServer Security & Firewall (CSF) may also be affected and should be evaluated independently.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
ConfigServer Security & Firewall (CSF) WebPros-maintained forkto a version that resolves this vulnerability.Fixed in 16.30
Event History
Frequently Asked Questions
Who can exploit this issue, and what level of access is required?
An unauthenticated remote attacker can exploit the flaw. Successful exploitation allows arbitrary commands to run as the CSF service account.
Which deployments have a confirmed fix?
WebPros addressed the issue in version 16.30 of its maintained CSF fork. Versions originally distributed by ConfigServer and other independently maintained forks may be affected if they contain the vulnerable code and should be evaluated separately.
What should organizations check if they use a non-WebPros CSF build?
Determine whether the build contains the vulnerable request-URL escaping code. The available information does not identify fixed versions for ConfigServer-distributed releases or other forks.