Junglewise Threat Intelligence

CVE-2026-65639: ConfigServer Security & Firewall OS command injection in advanced-rule parser

CVE-2026-65639 · Severity: info · CVSS 8.8 · Published 2026-09-10

Executive brief

ConfigServer Security & Firewall (CSF) is a Linux firewall and security application that manages firewall rules and threat detection. An OS command injection vulnerability in the advanced-rule parser allows a remote attacker who controls an allow/deny feed to execute arbitrary commands with root privileges, potentially enabling complete system compromise and unauthorized access to protected networks.

Technical details

This is an OS command injection vulnerability in the advanced-rule parser component of ConfigServer Security & Firewall, caused by insufficient validation of rule data supplied by configured allow/deny feeds. An attacker who controls a feed that CSF is configured to trust can inject arbitrary shell commands into rule data, which are executed with root privileges due to the way the parser processes feed input. The attack requires the victim to have configured CSF to use a malicious or compromised feed source. WebPros has patched this vulnerability in version 16.30; however, other forks and independently maintained versions may remain vulnerable and require independent evaluation.

Affected products

  • ConfigServer Security & Firewall versions prior to 16.30 (WebPros fork)

Timeline

  • 2026-09-10: disclosed
  • 2026-09-10: patched: WebPros released version 16.30 with fix

References

Related threats