PT-2026-89492 · Configserver+1 · Configserver Security & Firewall

CVE-2026-65638

·

Publicado

2026-09-10

·

Atualizado

2026-09-11

CVSS v4.0

9.2

Crítica

VetorAV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:N
🚨 [WEB HOSTING / REMOTE COMMAND EXECUTION] — AN UNAUTHENTICATED CONFIGSERVER SECURITY & FIREWALL FLAW CAN TURN ITS MESSENGER SERVICE INTO A COMMAND-EXECUTION PATH
Affected CSF versions span 14.00 through 16.29; 16.30+ contains the fix. The vulnerable functionality requires a particular non-default configuration, but the affected product commonly sits directly on public cPanel/WHM infrastructure.
CyberSignal Priority: 🔴 VERY HIGH
CVE-2026-65638 Product: ConfigServer Security & Firewall (CSF) Environment: commonly deployed with cPanel / WHM
A flaw in CSF's MESSENGER functionality can let a remote unauthenticated attacker inject arbitrary commands when the vulnerable feature is enabled under the required configuration. Current reporting says commands execute as the CSF service account—not automatically as root—which is an important distinction.

🔎 What happened

The problem involves improper escaping of a request URL handled through the CSF MESSENGER functionality, creating a shell-command-injection path. The vulnerability affects the original ConfigServer code as well as WebPros-maintained versions containing the vulnerable implementation.
The September 11 reporting identifies 14.00–16.29 as affected and recommends upgrading to 16.30 or later.

⚔️ Attack chain

Internet request ↓ CSF MESSENGER endpoint ↓ Attacker-controlled request data ↓ Improper shell escaping ↓ Command injection ↓ Execution as CSF service account ↓ Reconnaissance / file access / persistence ↓ Potential attempt at further privilege escalation

🎯 What is affected

The dangerous configuration requires:
MESSENGER enabled
and
a reCAPTCHA secret configured for that service.
The reporting says neither is enabled by default, materially reducing the exposure of stock configurations.
But administrators should verify configuration rather than assume they are unaffected—especially on internet-facing shared-hosting systems.

🧠 Why this matters

CSF is itself a defensive product.
That creates another security paradox:
THE TOOL BLOCKING UNTRUSTED NETWORK TRAFFIC ↓ BECOMES THE APPLICATION PROCESSING ATTACKER INPUT.
Internet-facing security infrastructure therefore deserves the same—or stronger—application-security discipline as the workloads behind it.

⚠️ Important caveat

The flaw does not automatically produce root access.
Current technical reporting says injected commands execute as CSF's unprivileged service account, and the vulnerable MESSENGER configuration is not enabled by default.
Do not headline this as:
“ANY CPANEL SERVER CAN BE ROOTED REMOTELY.”
That would be inaccurate.

🛡️ Defender action

Upgrade CSF to 16.30 or newer.
If immediate updating is impossible, current guidance recommends disabling MESSENGER (MESSENGER = 0) and restarting CSF/LFD as an interim mitigation.
Then investigate:
→ unexpected child shells from CSF-related processes → unusual commands from the service account → modified web content → persistence created after suspicious web requests → files written by the CSF account → attempts at local privilege escalation.
CyberSignal Insight:
A FIREWALL PLUGIN CAN BECOME AN INITIAL-ACCESS SERVICE THE MOMENT IT STARTS PARSING UNTRUSTED INTERNET INPUT.
Sources: cPanel · Belgian Centre for Cybersecurity · CVE/OpenCVE · current security reporting.

Correção

LPE

OS Command Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-65638

Produtos afetados

Configserver Security & Firewall