PT-2026-85316 · Configserver+1 · Configserver Security & Firewall+1
CVE-2026-67402
·
Published
2026-09-03
·
Updated
2026-09-04
CVSS v4.0
9.2
Critical
| Vector | AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
ConfigServer Security & Firewall versions prior to 16.31
Description
An insecure Apache configuration maps
/usr/bin as CGI (Common Gateway Interface) programs through the Messenger v3 HTTPS virtual host. This allows a remote unauthenticated attacker, even if their address is blocked, to request a mapped executable and execute arbitrary commands with the privileges of the Apache user. This issue specifically affects installations where CSF Messenger v3 and its HTTPS mode are enabled.Recommendations
Update to version 16.31.
Fix
Files Accessible to External Parties
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apache Http Server
Configserver Security & Firewall