Shell Command Injection Vulnerability in ConfigServer Security & Firewall by ConfigServer
CVE-2026-65638

9.2CRITICAL

Key Information:

Vendor

Webpros

Vendor
CVE Published:
10 September 2026

What is CVE-2026-65638?

An improper escaping of request URLs in ConfigServer Security & Firewall allows unauthenticated remote attackers to execute arbitrary commands as the CSF service account through shell command injection. This vulnerability impacts versions of the software that were originally provided by ConfigServer as well as certain versions maintained by WebPros that include the affected code. It is crucial for users operating these vulnerable versions to update to version 16.30 or evaluate their independently maintained versions to mitigate potential risks.

Affected Version(s)

ConfigServer Security & Firewall 14.00 < 16.30

ConfigServer Security & Firewall 14.00

References

CVSS V4

Score:
9.2
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.