PT-2026-85316 · Configserver+1 · Configserver Security & Firewall+1

CVE-2026-67402

·

Published

2026-09-03

·

Updated

2026-09-04

CVSS v4.0

9.2

Critical

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions ConfigServer Security & Firewall versions prior to 16.31
Description An insecure Apache configuration maps /usr/bin as CGI (Common Gateway Interface) programs through the Messenger v3 HTTPS virtual host. This allows a remote unauthenticated attacker, even if their address is blocked, to request a mapped executable and execute arbitrary commands with the privileges of the Apache user. This issue specifically affects installations where CSF Messenger v3 and its HTTPS mode are enabled.
Recommendations Update to version 16.31.

Fix

Files Accessible to External Parties

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-67402

Affected Products

Apache Http Server
Configserver Security & Firewall