Protection mechanism failure in OWASP ModSecurity Core Rule Set (CRS) - #VU153221
Published: October 3, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute commands with the privileges of the application process.
The vulnerability exists due to a protection mechanism failure in the 932 remote command execution rule family when command-injection payloads are placed in a URL path that the backend application passes to a shell. A remote attacker can send a crafted request containing a command-injection payload in the URL path to execute commands with the privileges of the application process.
Exploitation requires the backend application to pass a URL path segment into a shell.