Description
Webmin is a web-based system administration tool for Unix-like servers. Prior to version 2.640, for Webmin accounts that require a second authentication factor (typically TOTP), an attacker with knowledge of the username and password can bypass the 2FA requirement by using Basic authentication. Webmin is a web-based system administration tool for Unix-like servers. As a workaround, apply the patch from commit da18a16c84ae5c0b78cad79609cb0efb174000ec manually.
Published: 2026-07-20
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Webmin, a web‑based system administration interface for Unix‑like servers, has a flaw that allows an attacker who knows a valid username and password to bypass the required second authentication factor by using HTTP Basic authentication. This bypass grants the attacker full administrative privileges, compromising the confidentiality, integrity, and availability of the host. The vulnerability is identified as CWE‑287.

Affected Systems

This issue affects Webmin versions older than 2.640. The problem occurs for accounts configured to require two‑factor authentication, typically using TOTP, when HTTP Basic authentication remains enabled for administrative access.

Risk and Exploitability

The CVSS score of 5.3 indicates moderate severity. The EPSS score of < 1% reflects a very low but nonzero likelihood of exploitation at present. The vulnerability is not listed in CISA KEV. Exploitation requires the attacker to know a valid username/password and to send a Basic authentication header; once the 2FA requirement is bypassed, the attacker gains full administrative control over the server, enabling confidentiality, integrity, and availability compromise.

Generated by OpenCVE AI on July 30, 2026 at 18:54 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to Webmin version 2.640 or newer, which includes the official fix for the 2FA bypass.
  • If an upgrade is not yet possible, apply the patch from commit da18a16c84ae5c0b78cad79609cb0efb174000ec manually to the installation.
  • Disable or restrict HTTP Basic authentication for administrative interfaces, or block Basic auth for users with 2FA enabled using firewall or server‑level rules.

Generated by OpenCVE AI on July 30, 2026 at 18:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 21 Jul 2026 00:15:00 +0000

Type Values Removed Values Added
First Time appeared Webmin
Webmin webmin
Vendors & Products Webmin
Webmin webmin

Mon, 20 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 20 Jul 2026 17:15:00 +0000

Type Values Removed Values Added
Description Webmin is a web-based system administration tool for Unix-like servers. Prior to version 2.640, for Webmin accounts that require a second authentication factor (typically TOTP), an attacker with knowledge of the username and password can bypass the 2FA requirement by using Basic authentication. Webmin is a web-based system administration tool for Unix-like servers. As a workaround, apply the patch from commit da18a16c84ae5c0b78cad79609cb0efb174000ec manually.
Title Webmin 2FA requirement bypass
Weaknesses CWE-287
References
Metrics cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-07-20T17:41:48.414Z

Reserved: 2026-04-25T05:04:37.028Z

Link: CVE-2026-42210

cve-icon Vulnrichment

Updated: 2026-07-20T17:41:42.542Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-30T19:00:09Z

Weaknesses