Impact
Webmin, a web‑based system administration interface for Unix‑like servers, has a flaw that allows an attacker who knows a valid username and password to bypass the required second authentication factor by using HTTP Basic authentication. This bypass grants the attacker full administrative privileges, compromising the confidentiality, integrity, and availability of the host. The vulnerability is identified as CWE‑287.
Affected Systems
This issue affects Webmin versions older than 2.640. The problem occurs for accounts configured to require two‑factor authentication, typically using TOTP, when HTTP Basic authentication remains enabled for administrative access.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. The EPSS score of < 1% reflects a very low but nonzero likelihood of exploitation at present. The vulnerability is not listed in CISA KEV. Exploitation requires the attacker to know a valid username/password and to send a Basic authentication header; once the 2FA requirement is bypassed, the attacker gains full administrative control over the server, enabling confidentiality, integrity, and availability compromise.
OpenCVE Enrichment