Junglewise Threat Intelligence

CVE-2026-56021: Webmin information disclosure via regex bypass in module directories

CVE-2026-56021 · Severity: medium · CVSS 5.3 · Published 2026-06-18

Technologies: Webmin. Vendors: Webmin.

Executive brief

Webmin, a web-based interface for system administration, contains a security flaw that allows unauthorized individuals to read configuration files. An attacker can access sensitive information stored in files ending in .conf within the application's module directories without needing a username or password. This could lead to the exposure of system settings or other internal data, potentially aiding further attacks.

Technical details

An information disclosure vulnerability exists in Webmin due to an incorrect regular expression (CWE-185) and a lack of anchors (CWE-777) in the pattern used to restrict file access. Unauthenticated attackers can exploit this flaw to bypass security checks and read any file ending in the .conf extension located within module directories. The attack is carried out over the network without requiring user interaction or prior authentication. This issue was addressed in Webmin version 2.641.

Affected products

  • Webmin Webmin prior to 2.641

Timeline

  • 2026-05-11: patched: Webmin version 2.641 released
  • 2026-06-18: disclosed: CVE published to NVD

References

Related threats