PT-2026-50711 · Webmin · Webmin
CVSS v4.0
9.2
Critical
| Vector | AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Webmin versions prior to 2.641
Description
The Webmin HTTP server (miniserv.pl) improperly trusts a client-supplied HTTP header for SSL client certificate identity. This allows unauthenticated remote attackers to spoof certificate distinguished names (DNs)—the unique identifiers used in digital certificates—by sending a forged HTTP header. Consequently, an attacker can impersonate any user with a configured SSL client certificate without presenting a valid certificate, leading to a remote authentication bypass and potential full takeover of administrative accounts and managed systems.
Recommendations
Upgrade to version 2.641.
Exploit
Fix
Authentication Bypass by Spoofing
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Webmin