logo

Critical Webmin Vulnerabilities Enable User Impersonation and Root Access

ID: 5abce0ae-9ae7-5035-ba23-6f50ff100fd5

STIX ID: report--5abce0ae-9ae7-5035-ba23-6f50ff100fd5

Feed Name: ThreatCluster

Threat Score
75/100

Date Published: 2026-06-24

Date Updated: 2026-06-25

...
...

Webmin disclosed critical vulnerabilities affecting versions prior to 2.641, including a stored XSS (CVE-2026-22678) in the System and Server Status module that can be abused by limited-privilege users to impersonate other users and potentially escalate to root; administrators are urged to upgrade to the latest version.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.