ThreatCluster

Critical Webmin Vulnerabilities Enable User Impersonation and Root Access

3h ago GbhackersCybersecuritynews 82% similarity 73
Share:

Article Content

Browse articles
ThreatCluster

Webmin has disclosed critical vulnerabilities that allow attackers to impersonate any user and potentially gain root-level control. These flaws, affecting versions prior to 2.641, include stored cross-site scripting (XSS) and privilege escalation vulnerabilities. The stored XSS vulnerability, tracked as CVE-2026-22678, was published on 2026-05-21 and can be exploited by users with limited privileges to target root users. The vulnerabilities are present in the System and Server Status module, which is widely utilized for system monitoring. The impact is significant as it exposes systems to unauthorized access and control. Administrators are urged to upgrade to the latest version to mitigate these risks.

Key Points: • Webmin vulnerabilities allow user impersonation and root access. • CVE-2026-22678 is a stored XSS flaw affecting versions before 2.641. • Affected systems include Unix-like environments using Webmin for administration.

ThreatCluster AI

Timeline

2026-05-21
CVE-2026-22678 published
A stored XSS vulnerability in Webmin was disclosed, allowing limited users to exploit root accounts.
Gbhackers
2026-06-24
Webmin vulnerabilities disclosed
Critical security flaws in Webmin were reported, enabling user impersonation and privilege escalation.
Cybersecuritynews

Community

Browse all →