Executive brief
Webmin, a popular web-based interface for system administration, contains a security flaw in its mailboxes component. An attacker with low-level access can exploit this to save email attachments to unauthorized locations on the server. This could lead to a full system takeover, data loss, or the corruption of critical system files.
Technical details
A path traversal vulnerability (CWE-24) exists in Webmin's mailboxes component, specifically within 'mailboxes/detachall.cgi' and 'mailboxes/detach.cgi'. The application fails to properly sanitize filenames when saving email attachments, allowing an authenticated user with mailbox access to use '../' sequences to write files outside of the intended directory. This can be leveraged to overwrite sensitive system files or achieve remote code execution. The issue is resolved in Webmin version 2.640.
Affected products
- Webmin Webmin < 2.640
Timeline
- 2026-05-27: disclosed
- 2026-05-27: advisory