CVE-2026-56022CWE-308
CVE-2026-56022
Medium · published June 18, 2026
What it is
Webmin accepts basic authentication without session cookies when an attacker provides the 'User-Agent: webmin' header, allowing bypass of additional MFA requirements. Fixed in 2.640.
The record
Technical detail
- CVSS v3.1
- 5.3 · MEDIUM
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
- CVSS v4.0
- Not supplied
- EPSS
- 0.00555 · 44.2th percentile
- Weakness
- CWE-308 · Use of Single-factor Authentication
- Published
- 2026-06-18T21:16Z
Affected products (1)
| Product | Versions | Fixed in |
|---|
| webmin/webmin | < 2.640 | 2.640 |
References (4)
EPSS history
Timeline
18 JUN 16:11Z
Webmin MFA bypass
cvelistv5