logo

Critical Webmin Vulnerabilities Allow Attackers to Impersonate as Any User

ID: 84b48c16-1a44-5766-9c2d-96adf56a507e

STIX ID: report--84b48c16-1a44-5766-9c2d-96adf56a507e

Feed Name: cybersecurityNews.com

Threat Score
85/100

Date Published: 2026-06-24

Date Updated: 2026-06-24

Author: Abinaya

...
...

*Executive summary:* Multiple critical vulnerabilities in Webmin (pre-2.641) — including stored XSS enabling script execution as root, privilege escalation through the Help feature, mail-module XSS and unsafe attachment handling, and 2FA bypass via HTTP Basic Authentication — can be chained to achieve full system compromise; administrators are advised to upgrade immediately, disable unnecessary modules, enforce strict access controls, and disable Basic Auth where possible.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.