Description
An insecure Apache configuration in ConfigServer Security & Firewall maps /usr/bin as CGI programs through the Messenger v3 HTTPS virtual host. A remote unauthenticated attacker whose address is blocked can request a mapped executable and run arbitrary commands as the Apache user. The vulnerability affects installations where CSF Messenger v3 and its HTTPS mode are enabled. WebPros addressed the vulnerability in version 16.31.
Published: 2026-09-03
Score: 9.2 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Patch Immediately
AI Analysis

Impact

An insecure Apache configuration in ConfigServer Security & Firewall maps the /usr/bin directory as CGI programs through the Messenger v3 HTTPS virtual host. A remote, unauthenticated attacker can request one of these mapped executables and execute arbitrary commands as the Apache user, giving full control over the system. This flaw is a classic case of unrestricted command execution as defined by CWE‑552.

Affected Systems

All ConfigServer Security & Firewall installations that have Messenger v3 enabled and are configured to use HTTPS are affected. The issue exists in every version prior to 16.31. The product is distributed by ConfigServer and WebPros.

Risk and Exploitability

The CVSS base score of 9.2 categorizes this vulnerability as critical. EPSS is not available, and it is not in CISA’s KEV catalog, yet the lack of a publicly known exploit does not diminish the potential impact. An attacker can reach the vulnerable configuration from the Internet without any prior authentication, provided that the /usr/bin mapping and Messenger v3 HTTPS virtual host remain active. Successful exploitation grants the attacker Apache‑user execution privileges, enabling complete compromise of the affected system.

Generated by OpenCVE AI on September 4, 2026 at 01:51 UTC.

Remediation

Vendor Workaround

Disable Messenger v3 by setting MESSENGERV3 = "0" until version 16.31 can be installed. This is the shipped default.


OpenCVE Recommended Actions

  • Upgrade to ConfigServer Security & Firewall version 16.31 or later, which removes the vulnerable mapping.
  • If upgrading is not possible immediately, disable Messenger v3 by setting MESSENGERV3="0" in the CSF configuration file.
  • Verify that the /usr/bin directory is no longer exposed as a CGI directory in the Apache configuration and that the Messenger v3 HTTPS virtual host is disabled.

Generated by OpenCVE AI on September 4, 2026 at 01:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 05 Sep 2026 22:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 04 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Configserver
Configserver configserver Security Firewall
Vendors & Products Configserver
Configserver configserver Security Firewall

Fri, 04 Sep 2026 02:15:00 +0000

Type Values Removed Values Added
Title Remote Command Execution via Insecure Apache CGI Mapping in ConfigServer Security & Firewall Messenger v3

Fri, 04 Sep 2026 00:00:00 +0000

Type Values Removed Values Added
Description An insecure Apache configuration in ConfigServer Security & Firewall maps /usr/bin as CGI programs through the Messenger v3 HTTPS virtual host. A remote unauthenticated attacker whose address is blocked can request a mapped executable and run arbitrary commands as the Apache user. The vulnerability affects installations where CSF Messenger v3 and its HTTPS mode are enabled. WebPros addressed the vulnerability in version 16.31.
Weaknesses CWE-552
References
Metrics cvssV4_0

{'score': 9.2, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:N'}


Subscriptions

Configserver Configserver Security Firewall
cve-icon MITRE

Status: PUBLISHED

Assigner: hackerone

Published:

Updated: 2026-09-04T19:47:36.330Z

Reserved: 2026-07-29T15:00:02.294Z

Link: CVE-2026-67402

cve-icon Vulnrichment

Updated: 2026-09-04T19:47:32.422Z

cve-icon NVD

Status : Deferred

Published: 2026-09-04T00:17:13.690

Modified: 2026-09-09T15:41:24.427

Link: CVE-2026-67402

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-04T15:15:14Z

Weaknesses
  • CWE-552

    Files or Directories Accessible to External Parties