logo

Critical Webmin Stored XSS Vulnerability Lets Untrusted Users Exploit Root Accounts

ID: 5eb389bf-3bde-516f-b60d-b8c0e649268c

STIX ID: report--5eb389bf-3bde-516f-b60d-b8c0e649268c

Feed Name: Cyber Press

Threat Score
85/100

Date Published: 2026-06-24

Date Updated: 2026-06-24

Author: Lucas Martin

...
...

A critical stored XSS in Webmin's System and Server Status module (CVE-2026-22678) lets untrusted users inject scripts that execute as root when notification templates are viewed; Webmin 2.641 fixes this. Webmin 2.640 also patched SVG XSS (CVE-2026-49102), email attachment filename overwrite (CVE-2026-49103), and a 2FA bypass via Basic Authentication (CVE-2026-42210/CVE-2026-56022). Administrators are urged to upgrade immediately and audit permissions for untrusted users.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.