XSS Vulnerability in Webmin Affects Unix-like Server Administration
CVE-2026-49243

5.1MEDIUM

Key Information:

Vendor

Webmin

Status
Vendor
CVE Published:
29 September 2026

What is CVE-2026-49243?

Webmin, a web-based administration tool for Unix-like servers, is susceptible to a Cross-Site Scripting (XSS) vulnerability that can be triggered when users click on malicious links targeting their server. This flaw allows an attacker to execute harmful commands on the server, compromising the system's integrity and security. Users are urged to upgrade to Webmin version 2.650, where this issue has been addressed and resolved. Regular updates and vigilance are essential to ensure the safety of server environments.

Affected Version(s)

webmin < 2.650

References

CVSS V4

Score:
5.1
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.