CVE-2026-56021CWE-185CWE-777

CVE-2026-56021

Medium · published June 18, 2026

CVSS v3.1
5.3
EPSS
0%
Percentile
39.5
In the wild
Unconfirmed
What it is

Webmin allows unauthenticated attackers to read the contents of any file ending in .conf within module directories, due to a bypassable regex pattern.

The record
Technical detail
CVSS v3.1
5.3 · MEDIUM
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CVSS v4.0
Not supplied
EPSS
0.00476 · 39.5th percentile
Weaknesses
CWE-185 · Incorrect Regular Expression; CWE-777 · Regular Expression without Anchors
Published
2026-06-18T21:16Z
Affected products (1)
ProductVersionsFixed in
webmin/webmin< 1.2901.290
References (4)
EPSS history
Timeline
  • 18 JUN 16:11Z
    Webmin information disclosure via regex pattern
    cvelistv5