Junglewise Threat Intelligence

CVE-2026-56020: Webmin authentication bypass via SSL certificate spoofing in miniserv.pl

CVE-2026-56020 · Severity: high · CVSS 8.1 · Published 2026-06-18

Technologies: Webmin. Vendors: Webmin.

Executive brief

Webmin, a popular web-based interface for system administration, contains a vulnerability that allows attackers to bypass security checks and log in as any user. By sending a specially crafted web request, an attacker can trick the system into believing they have a valid security certificate. This could lead to a complete takeover of the server and unauthorized access to sensitive administrative functions.

Technical details

An authentication bypass vulnerability exists in Webmin's miniserv.pl component due to improper validation of proxy-provided HTTP headers. When Webmin is configured to trust remote IP addresses from a proxy, it may incorrectly trust SSL client certificate information provided in forged HTTP headers from clients connecting directly to the server. An unauthenticated remote attacker can exploit this by spoofing certificate Distinguished Names (DNs) to impersonate any user configured for certificate-based authentication. This vulnerability is classified as CWE-290 (Authentication Bypass by Spoofing). The issue is resolved in Webmin version 2.641.

Affected products

  • Webmin Webmin versions prior to 2.641

Timeline

  • 2026-05-11: patched: Webmin version 2.641 released
  • 2026-06-18: disclosed: CVE published to NVD

References

Related threats