Critical Webmin Vulnerabilities Enable User Impersonation and Root Access
Article Content
- •Webmin vulnerabilities allow user impersonation and root access.
- •CVE-2026-22678 is a stored XSS flaw affecting versions before 2.641.
- •Affected systems include Unix-like environments using Webmin for administration.
Webmin has disclosed critical vulnerabilities that allow attackers to impersonate any user and potentially gain root-level control. These flaws, affecting versions prior to 2.641, include stored cross-site scripting (XSS) and privilege escalation vulnerabilities. The stored XSS vulnerability, tracked as CVE-2026-22678, was published on 2026-05-21 and can be exploited by users with limited privileges to target root users. The vulnerabilities are present in the System and Server Status module, which is widely utilized for system monitoring. The impact is significant as it exposes systems to unauthorized access and control. Administrators are urged to upgrade to the latest version to mitigate these risks.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track CVE-2026-22678 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Twitch Chat Messages Exploit OBS Studio via Chromium Vulnerability A vulnerability in OBS Studio allows malicious Twitch chat messages to execute native code on streamers' Windows PCs. This exploit targets users running OBS Studio version 32.2.2 or older, leveraging a cross-site scripting (XSS) flaw in custom overlays that render viewer messages as unsanitized HTML. The attack…