Webmin 2.641 Fixes Three Vulnerabilities Including a Critical Auth Bypass
ID: 38f6a396-cb18-56e6-a2e9-d984c5574223
STIX ID: report--38f6a396-cb18-56e6-a2e9-d984c5574223
Feed Name: securityonline.info
Threat Score
Webmin released version 2.641 to patch three vulnerabilities—most critically a HTTP header authentication bypass (CVSSv4 9.2) that allows unauthenticated impersonation of any configured user, plus an MFA bypass and a regex-based configuration disclosure; patches are available, no confirmed exploitation yet, and admins should update immediately and restrict access.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
