Junglewise Threat Intelligence

CVE-2026-49102: Webmin XSS in mailboxes component via SVG attachment

CVE-2026-49102 · Severity: medium · CVSS 6.1 · Published 2026-05-27

Technologies: Webmin. Vendors: Webmin.

Executive brief

Webmin is a web-based interface for system administration on Unix-like systems. A security vulnerability in its email management component allows an attacker to send a specially crafted email attachment that, when viewed by a user, executes malicious scripts in their browser. This could lead to unauthorized actions being performed on behalf of the user or the theft of sensitive session information.

Technical details

A Cross-Site Scripting (XSS) vulnerability exists in Webmin's mailboxes component, specifically within 'mailboxes/detach.cgi'. The issue stems from the application serving SVG document attachments using the 'image/svg+xml' MIME type instead of a safer alternative like 'text/plain'. Because SVG files can contain embedded JavaScript, an attacker can send an email with a malicious SVG attachment; when a victim views or detaches this file through the Webmin interface, the script executes within the context of the victim's session. This is a reflected XSS attack requiring user interaction. The vulnerability is addressed in version 2.640 by improving attachment handling.

Affected products

  • Webmin Webmin before 2.640

Timeline

  • 2026-05-27: disclosed
  • 2026-05-27: advisory

References

Related threats