CVE-2026-65639: OS Command Injection
OS command injection in the advanced-rule parser of ConfigServer Security & Firewall allows a remote attacker who controls a configured allow/deny feed to execute arbitrary commands as root, due to insufficient validation of feed-supplied rule data.
The vulnerability affects versions of the software originally distributed by ConfigServer, as well as versions of the WebPros-maintained fork that contain the vulnerable code. WebPros has addressed the vulnerability in version 16.30. Other forks or independently maintained versions of ConfigServer Security & Firewall (CSF) may also be affected and should be evaluated independently.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
ConfigServer Security & Firewall (CSF)to a version that resolves this vulnerability.Fixed in 16.30
Event History
Frequently Asked Questions
Who is exposed to exploitation?
Systems are exposed if they run a vulnerable ConfigServer-distributed CSF version or a WebPros-maintained fork containing the vulnerable code, and use an allow/deny feed that an attacker can control. Other forks or independently maintained CSF versions require separate evaluation.
What access does an attacker need?
The attacker needs control over a configured allow/deny feed so they can supply malicious advanced-rule data. Successful exploitation can execute arbitrary commands as root.
Which version fixes the WebPros-maintained fork?
WebPros addressed the issue in version 16.30.
What can be done while patching is delayed?
The provided information identifies attacker control of a configured allow/deny feed as the exploitation prerequisite. Review configured feeds and prevent untrusted parties from controlling their contents until the affected software can be updated.