CVE-2026-67402
Last modified
CVE-2026-67402 is a critical-severity vulnerability rated 9.2/10 on the CVSS scale. An insecure Apache configuration in ConfigServer Security & Firewall maps /usr/bin as CGI programs through the Messenger v3 HTTPS virtual host. A remote unauthenticated attacker whose address is blocked can request a mapped executable and run arbitrary commands as the Apache user. EPSS estimates a 0.32% chance of exploitation in the next 30 days.
Description
An insecure Apache configuration in ConfigServer Security & Firewall maps /usr/bin as CGI programs through the Messenger v3 HTTPS virtual host. A remote unauthenticated attacker whose address is blocked can request a mapped executable and run arbitrary commands as the Apache user. The vulnerability affects installations where CSF Messenger v3 and its HTTPS mode are enabled. WebPros addressed the vulnerability in version 16.31.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| WebPros | ConfigServer Security & Firewall | >= 14.02, < 16.31 |
| ConfigServer | ConfigServer Security & Firewall | >= 14.02, < * |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-67402?
How severe is CVE-2026-67402?
How do I fix CVE-2026-67402?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-67395A path traversal vulnerability exists in Sage Employee Self …5.9
- CVE-2026-67397Path traversal in Plesk 18.0.79.9 and earlier and 18.0.80 th…8.5
- CVE-2026-67398Missing authorization vulnerability has been discovered in 2…8.2
- CVE-2026-67399Deserialization of untrusted data in WHMCS 9.0.0 before 9.0.…9.3
- CVE-2026-6740The Nexter Blocks – Gutenberg Blocks, Page Builder & AI Webs…6.4
- CVE-2026-67401A vulnerability in cPanel allows a mail-enabled account to a…9.9
- CVE-2026-67403Cash Collect contains an improper authorization vulnerabilit…9
- CVE-2026-67404RabbitMQ is a messaging and streaming broker. Prior to versi…9.2
- CVE-2026-67405RabbitMQ is a messaging and streaming broker. Prior to versi…5.3
- CVE-2026-67406RabbitMQ is a messaging and streaming broker. From 4.0.0 unt…4.6
- CVE-2026-67407RabbitMQ is a messaging and streaming broker. From 4.0.0 unt…5.1
- CVE-2026-67408RabbitMQ is a messaging and streaming broker. From 4.1.0 unt…7.1
Are you affected by CVE-2026-67402?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
