Unrated severityNVD Advisory· Published Jun 18, 2026· Updated Jun 19, 2026
Webmin HTTP header authentication bypass
CVE-2026-56020
Description
The Webmin HTTP server (miniserv.pl) allows unauthenticated attackers to impersonate any user with a configured SSL client certificate by sending a forged HTTP header. A remote attacker can spoof certificate DNs and authenticate as any user. Fixed in 2.641.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1Patches
Vulnerability mechanics
References
4- github.com/webmin/webmin/releases/tag/2.641mitrerelease-notes
- webmin.com/security/mitrerelease-notes
- www.cve.org/CVERecordmitrevdb-entry
- raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-169-02.jsonmitre
News mentions
1- Critical Webmin Vulnerabilities Allow Attackers to Impersonate as Any UserCyber Security News · Jun 24, 2026