CVE-2026-56021CWE-185CWE-777
CVE-2026-56021
Medium · published June 18, 2026
What it is
Webmin allows unauthenticated attackers to read the contents of any file ending in .conf within module directories, due to a bypassable regex pattern.
The record
Technical detail
- CVSS v3.1
- 5.3 · MEDIUM
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- CVSS v4.0
- Not supplied
- EPSS
- 0.00476 · 39.5th percentile
- Weaknesses
- CWE-185 · Incorrect Regular Expression; CWE-777 · Regular Expression without Anchors
- Published
- 2026-06-18T21:16Z
Affected products (1)
| Product | Versions | Fixed in |
|---|
| webmin/webmin | < 1.290 | 1.290 |
References (4)
EPSS history
Timeline