Junglewise Threat Intelligence

CVE-2026-49103: Webmin path traversal in mailboxes component

CVE-2026-49103 · Severity: info · CVSS 9.4 · Published 2026-05-27

Technologies: Webmin. Vendors: Webmin.

Executive brief

Webmin, a popular web-based interface for system administration, contains a security flaw in its mailboxes component. An attacker with low-level access can exploit this to save email attachments to unauthorized locations on the server. This could lead to a full system takeover, data loss, or the corruption of critical system files.

Technical details

A path traversal vulnerability (CWE-24) exists in Webmin's mailboxes component, specifically within 'mailboxes/detachall.cgi' and 'mailboxes/detach.cgi'. The application fails to properly sanitize filenames when saving email attachments, allowing an authenticated user with mailbox access to use '../' sequences to write files outside of the intended directory. This can be leveraged to overwrite sensitive system files or achieve remote code execution. The issue is resolved in Webmin version 2.640.

Affected products

  • Webmin Webmin < 2.640

Timeline

  • 2026-05-27: disclosed
  • 2026-05-27: advisory

References

Related threats