SB2026100310 - Multiple vulnerabilities in OWASP ModSecurity Core Rule Set (CRS)



SB2026100310 - Multiple vulnerabilities in OWASP ModSecurity Core Rule Set (CRS)

Published: October 3, 2026

Security Bulletin ID SB2026100310
CSH Severity
Medium
Patch available
YES
Number of vulnerabilities 3
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

Medium 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 3 vulnerabilities.


1) Protection mechanism failure (CVE-ID: N/A)

CWE-ID: CWE-693 - Protection Mechanism Failure

CVSSv4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to execute commands with the privileges of the application process.

The vulnerability exists due to a protection mechanism failure in the 932 remote command execution rule family when command-injection payloads are placed in a URL path that the backend application passes to a shell. A remote attacker can send a crafted request containing a command-injection payload in the URL path to execute commands with the privileges of the application process.

Exploitation requires the backend application to pass a URL path segment into a shell.


2) Improper Handling of Case Sensitivity (CVE-ID: N/A)

CWE-ID: CWE-178 - Improper Handling of Case Sensitivity

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass charset allow-list enforcement and evade downstream detection rules.

The vulnerability exists due to improper handling of case sensitivity in rule 920480 in the REQUEST-920-PROTOCOL-ENFORCEMENT.conf rule set when processing Content-Type request headers with uppercase or mixed-case charset parameter names. A remote attacker can send a request with a non-lowercase CHARSET parameter name to bypass charset allow-list enforcement and evade downstream detection rules.

The issue affects deployments using paranoia level 1 or 2 that rely on rule 920480; encoding-based filter evasion additionally depends on the backend honoring the declared charset when decoding the request body.


3) Improper Handling of Extra Parameters (CVE-ID: N/A)

CWE-ID: CWE-235 - Improper Handling of Extra Parameters

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass multipart charset protections.

The vulnerability exists due to improper handling of extra parameters in rule 922100 when processing multipart requests containing an additional argument or an allowed charset after a blocked charset. A remote attacker can send a crafted multipart request to bypass multipart charset protections.


Remediation

Install update from vendor's website.