CVE-2026-67402
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
An insecure Apache configuration in ConfigServer Security & Firewall maps /usr/bin as CGI programs through the Messenger v3 HTTPS virtual host. A remote unauthenticated attacker whose address is blocked can request a mapped executable and run arbitrary commands as the Apache user. The vulnerability affects installations where CSF Messenger v3 and its HTTPS mode are enabled. WebPros addressed the vulnerability in version 16.31.
| CWE | CWE-552 |
| Vendor | webpros |
| Product | configserver security & firewall |
| Published | Sep 3, 2026 |
Stay Ahead of the Next One
Get instant alerts for webpros configserver security & firewall
Be the first to know when new unknown vulnerabilities affecting webpros configserver security & firewall are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
WebPros / ConfigServer Security & Firewall
14.02 < 16.31
ConfigServer / ConfigServer Security & Firewall
14.02 < *