logo

Webmin Stored XSS Vulnerability Lets Attackers Exploit Root Users

ID: 58733a49-58c6-50b1-aeff-f2ad8027d3b9

STIX ID: report--58733a49-58c6-50b1-aeff-f2ad8027d3b9

Feed Name: GBHackers

Threat Score
70/100

Date Published: 2026-06-24

Date Updated: 2026-06-24

Author: Divya

...
...

A stored XSS vulnerability (CVE-2026-22678) in Webmin versions prior to 2.641 allows an authenticated, untrusted user who can create or edit notification email templates to inject JavaScript that executes when privileged users (including root) view the template; this can enable session hijacking, credential theft, and unauthorized administrative actions. The issue resides in the System and Server Status module due to improper input sanitization, was responsibly disclosed by a researcher, and has been fixed in Webmin 2.641—administrators are advised to upgrade immediately, audit templates, and review permissions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.