Description
Webmin accepts basic authentication without session cookies when an attacker provides the 'User-Agent: webmin' header, allowing bypass of additional MFA requirements. Fixed in 2.641.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Thu, 18 Jun 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Webmin accepts basic authentication without session cookies when an attacker provides the 'User-Agent: webmin' header, allowing bypass of additional MFA requirements. Fixed in 2.641. | |
| Title | Webmin MFA bypass | |
| Weaknesses | CWE-308 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: cisa-cg
Published:
Updated: 2026-06-18T16:11:22.057Z
Reserved: 2026-06-18T14:15:41.670Z
Link: CVE-2026-56022
No data.
No data.
No data.
OpenCVE Enrichment
No data.
Weaknesses
-
CWE-308
Use of Single-factor Authentication