PT-2026-50713 · Webmin · Webmin

·

CVE-2026-56022

·

Published

2026-06-18

·

Updated

2026-06-24

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Webmin versions prior to 2.641
Description Webmin accepts basic authentication without session cookies when an attacker provides the 'User-Agent: webmin' header. This behavior allows the bypass of additional multi-factor authentication (MFA) requirements. There have been reports of increased actor activities targeting this issue.
Recommendations Update to version 2.641.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-56022

Affected Products

Webmin