OS Command Injection in ConfigServer Security & Firewall by ConfigServer
CVE-2026-65639

9.5CRITICAL

Key Information:

Vendor

Webpros

Vendor
CVE Published:
10 September 2026

What is CVE-2026-65639?

A vulnerability exists in the advanced-rule parser of ConfigServer Security & Firewall, allowing a remote attacker controlling a configured allow/deny feed to execute arbitrary commands as root. This is due to insufficient validation of rule data supplied by the feed. The vulnerable versions include those originally released by ConfigServer and those maintained by WebPros that contain the exploitable code. Organizations using affected versions should consider upgrading to version 16.30 or evaluate their systems urgently to mitigate potential risks.

Affected Version(s)

ConfigServer Security & Firewall 2.15 < 16.30

ConfigServer Security & Firewall 2.15

References

CVSS V4

Score:
9.5
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.