Webmin accepts basic authentication without session cookies when an attacker provides the 'User-Agent: webmin' header, allowing bypass of additional MFA requirements. Fixed in 2.641.
References
Configurations
No configuration.
History
18 Jun 2026, 17:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-06-18 17:16
Updated : 2026-06-24 21:16
NVD link : CVE-2026-56022
Mitre link : CVE-2026-56022
CVE.ORG link : CVE-2026-56022
JSON object : View
Products Affected
No product.
CWE
CWE-308
Use of Single-factor Authentication
