logo

Webmin 2.641 Fixes Three Vulnerabilities Including a Critical Auth Bypass

ID: 38f6a396-cb18-56e6-a2e9-d984c5574223

STIX ID: report--38f6a396-cb18-56e6-a2e9-d984c5574223

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2026-06-24

Date Updated: 2026-06-24

Author: Do Son

...
...

Webmin released version 2.641 to patch three vulnerabilities—most critically a HTTP header authentication bypass (CVSSv4 9.2) that allows unauthenticated impersonation of any configured user, plus an MFA bypass and a regex-based configuration disclosure; patches are available, no confirmed exploitation yet, and admins should update immediately and restrict access.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.