The Webmin HTTP server (miniserv.pl) allows unauthenticated attackers to impersonate any user with a configured SSL client certificate by sending a forged HTTP header. A remote attacker can spoof certificate DNs and authenticate as any user. Fixed in 2.641.
References
Configurations
No configuration.
History
19 Jun 2026, 06:17
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-06-18 17:16
Updated : 2026-06-22 17:52
NVD link : CVE-2026-56020
Mitre link : CVE-2026-56020
CVE.ORG link : CVE-2026-56020
JSON object : View
Products Affected
No product.
CWE
CWE-290
Authentication Bypass by Spoofing
