Critical Webmin Stored XSS Vulnerability Lets Untrusted Users Exploit Root Accounts
ID: 5eb389bf-3bde-516f-b60d-b8c0e649268c
STIX ID: report--5eb389bf-3bde-516f-b60d-b8c0e649268c
Feed Name: Cyber Press
Threat Score
A critical stored XSS in Webmin's System and Server Status module (CVE-2026-22678) lets untrusted users inject scripts that execute as root when notification templates are viewed; Webmin 2.641 fixes this. Webmin 2.640 also patched SVG XSS (CVE-2026-49102), email attachment filename overwrite (CVE-2026-49103), and a 2FA bypass via Basic Authentication (CVE-2026-42210/CVE-2026-56022). Administrators are urged to upgrade immediately and audit permissions for untrusted users.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
