Medium severity5.3NVD Advisory· Published Jun 18, 2026· Updated Aug 11, 2026
CVE-2026-56022
CVE-2026-56022
Description
Webmin accepts basic authentication without session cookies when an attacker provides the 'User-Agent: webmin' header, allowing bypass of additional MFA requirements. Fixed in 2.640.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3Patches
Vulnerability mechanics
References
4- webmin.com/security/nvdVendor Advisory
- github.com/webmin/webmin/releases/tag/2.640nvdRelease Notes
- raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-169-02.jsonnvdVDB Entry
- www.cve.org/CVERecordnvdVDB Entry
News mentions
2- ⚡ Weekly Recap: Proxy Botnets, Browser Ransomware, AI Agent Tricks, Fake PoC Malware and MoreThe Hacker News · Jul 6, 2026
- Critical Webmin Vulnerabilities Allow Attackers to Impersonate as Any UserCyber Security News · Jun 24, 2026