PT-2026-50711 · Webmin · Webmin

·

CVE-2026-56020

·

Published

2026-06-18

·

Updated

2026-06-22

CVSS v4.0

9.2

Critical

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Webmin versions prior to 2.641
Description The Webmin HTTP server (miniserv.pl) improperly trusts a client-supplied HTTP header for SSL client certificate identity. This allows unauthenticated remote attackers to spoof certificate distinguished names (DNs)—the unique identifiers used in digital certificates—by sending a forged HTTP header. Consequently, an attacker can impersonate any user with a configured SSL client certificate without presenting a valid certificate, leading to a remote authentication bypass and potential full takeover of administrative accounts and managed systems.
Recommendations Upgrade to version 2.641.

Exploit

Fix

Authentication Bypass by Spoofing

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-56020

Affected Products

Webmin