{"id":"CVE-2026-65639","title":"OS command injection in the advanced-rule parser of ConfigServer Security & Firewall allows a remote attacker who controls a configured allow/deny feed to execute arbitrary commands as root, due to insufficient validation of feed-supplie…","summary":"OS command injection in the advanced-rule parser of ConfigServer Security & Firewall allows a remote attacker who controls a configured allow/deny feed to execute arbitrary commands as root, due to insufficient validation of feed-supplie…","severity":"critical","cvss":9.5,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H","cvssSource":"cna","cwe":["CWE-78"],"vendor":"WebPros","product":"ConfigServer Security & Firewall","affected":["configserver_security_firewall >= 2.15 < 16.30","security_firewall >= 2.15 < *"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"total","timestamp":"2026-09-10T18:19:30.960257Z"},"published":"2026-09-10","updated":"2026-09-10","sourceUpdated":"2026-09-10T18:19:47.504Z","source":"CVEORG","sourceUrl":"https://www.cve.org/CVERecord?id=CVE-2026-65639","references":[{"url":"https://support.cpanel.net/hc/en-us/articles/43387923160343-Security-CVE-2026-65639-CSF-Security-Release"}],"tags":["cve.org"],"epss":0.01611,"epssPercentile":0.74878,"ingestedAt":"2026-09-11T17:50:33.679Z","slug":"CVE-2026-65639","body":"## Overview\n\nOS command injection in the advanced-rule parser of ConfigServer Security & Firewall allows a remote attacker who controls a configured allow/deny feed to execute arbitrary commands as root, due to insufficient validation of feed-supplied rule data.\n\nThe vulnerability affects versions of the software originally distributed by ConfigServer, as well as versions of the WebPros-maintained fork that contain the vulnerable code. WebPros has addressed the vulnerability in version 16.30. Other forks or independently maintained versions of ConfigServer Security & Firewall (CSF) may also be affected and should be evaluated independently.\n\n## Affected\n\n- `configserver_security_firewall >= 2.15 < 16.30`\n- `security_firewall >= 2.15 < *`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"midnight","depthScore":53,"depthScoreParts":{"impact":52.3,"likelihood":0.3,"exploitation":0,"ransomware":0},"changes":[]}