Shell Command Injection Vulnerability in ConfigServer Security & Firewall by ConfigServer
CVE-2026-65638
9.2CRITICAL
What is CVE-2026-65638?
An improper escaping of request URLs in ConfigServer Security & Firewall allows unauthenticated remote attackers to execute arbitrary commands as the CSF service account through shell command injection. This vulnerability impacts versions of the software that were originally provided by ConfigServer as well as certain versions maintained by WebPros that include the affected code. It is crucial for users operating these vulnerable versions to update to version 16.30 or evaluate their independently maintained versions to mitigate potential risks.
Affected Version(s)
ConfigServer Security & Firewall 14.00 < 16.30
ConfigServer Security & Firewall 14.00
