Junglewise Threat Intelligence

CVE-2026-67402: ConfigServer Security & Firewall arbitrary command execution via insecure CGI mapping

CVE-2026-67402 · Severity: info · Published 2026-09-04

Vendors: WebPros.

Executive brief

ConfigServer Security & Firewall (CSF) is a server-level firewall and security tool used to protect Linux servers. When CSF Messenger v3 is enabled in HTTPS mode, an insecure Apache configuration maps system binaries as CGI programs, allowing an attacker to execute arbitrary commands on the server as the Apache user, potentially compromising the entire server and any hosted applications.

Technical details

The vulnerability is an insecure Apache configuration in ConfigServer Security & Firewall's Messenger v3 HTTPS virtual host that maps /usr/bin as a CGI directory, treating executable system binaries as CGI scripts. An unauthenticated remote attacker can request a mapped executable through the web server to achieve arbitrary command execution with Apache user privileges. The vulnerability requires CSF Messenger v3 and its HTTPS mode to be enabled. WebPros released version 16.31 to address this configuration flaw by removing or properly restricting the CGI mapping.

Affected products

  • WebPros ConfigServer Security & Firewall before 16.31

Timeline

  • 2026-09-04: disclosed
  • 2026-09-03: patched: Version 16.31 released

References