CVE-2026-42210
- EPSS 0.42%
- Veröffentlicht 20.07.2026 17:03:09
- Zuletzt bearbeitet 23.07.2026 18:04:31
Webmin is a web-based system administration tool for Unix-like servers. Prior to version 2.640, for Webmin accounts that require a second authentication factor (typically TOTP), an attacker with knowledge of the username and password can bypass the 2...
CVE-2026-56020
- EPSS 0.5%
- Veröffentlicht 18.06.2026 16:12:05
- Zuletzt bearbeitet 11.08.2026 16:17:33
The Webmin HTTP server (miniserv.pl) allows unauthenticated attackers to impersonate any user with a configured SSL client certificate by sending a forged HTTP header. A remote attacker can spoof certificate DNs and authenticate as any user. Fixed in...
CVE-2026-56021
- EPSS 0.48%
- Veröffentlicht 18.06.2026 16:11:46
- Zuletzt bearbeitet 11.08.2026 12:17:50
Webmin allows unauthenticated attackers to read the contents of any file ending in .conf within module directories, due to a bypassable regex pattern.
CVE-2026-56022
- EPSS 0.56%
- Veröffentlicht 18.06.2026 16:11:22
- Zuletzt bearbeitet 11.08.2026 17:05:35
Webmin accepts basic authentication without session cookies when an attacker provides the 'User-Agent: webmin' header, allowing bypass of additional MFA requirements. Fixed in 2.640.
CVE-2026-49102
- EPSS 0.22%
- Veröffentlicht 27.05.2026 15:16:34
- Zuletzt bearbeitet 27.05.2026 19:49:48
Webmin before 2.640 allows mailboxes/detach.cgi XSS via an SVG document attachment that is viewed in the mailboxes component, because image/svg+xml is used instead of a safe type (e.g., text/plain).
CVE-2026-49103
- EPSS 0.4%
- Veröffentlicht 27.05.2026 15:16:34
- Zuletzt bearbeitet 27.05.2026 19:49:48
Webmin before 2.640 does not safely construct a filename for saving of an attachment within the mailboxes component. This occurs in mailboxes/detachall.cgi.
CVE-2026-22678
- EPSS 0.22%
- Veröffentlicht 21.05.2026 20:59:52
- Zuletzt bearbeitet 23.07.2026 16:10:00
Webmin before 2.641 contains a stored cross-site scripting vulnerability in the email template description field of the System and Server Status module that allows low-privileged authenticated attackers to execute arbitrary JavaScript in the browser ...
CVE-2025-67738
- EPSS 0.35%
- Veröffentlicht 11.12.2025 06:34:10
- Zuletzt bearbeitet 15.04.2026 00:35:42
squid/cachemgr.cgi in Webmin before 2.600 does not properly quote arguments. This is relevant if Webmin's Squid module and its Cache Manager feature are available, and an untrusted party is able to authenticate to Webmin and has certain Cache Manager...
CVE-2025-61541
- EPSS 0.43%
- Veröffentlicht 16.10.2025 00:00:00
- Zuletzt bearbeitet 06.11.2025 22:20:36
Webmin 2.510 is vulnerable to a Host Header Injection in the password reset functionality (forgot_send.cgi). The reset link sent to users is constructed using the HTTP Host header via get_webmin_email_url(). An attacker can manipulate the Host header...
CVE-2024-12828
- EPSS 33.47%
- Veröffentlicht 30.12.2024 17:15:07
- Zuletzt bearbeitet 14.08.2025 18:41:57
Webmin CGI Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Webmin. Authentication is required to exploit this vulnerability. The specific flaw ...