CVE-2026-22678Disclosure(webmin / webmin)

LOWCVSS 5.1 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch webmin webmin systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Webmin before 2.641 contains a stored cross-site scripting vulnerability in the email template description field of the System and Server Status module that allows low-privileged authenticated attackers to execute arbitrary JavaScript in the browser context of administrators by injecting unsanitized input stored in save_tmpl.cgi and rendered unescaped in list_tmpls.cgi.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • webmin

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • Peaked 1d ago at 3 mentions (2026-06-24); latest day: 1
  • 4 total mentions across 2 days

Affected systems

Vendors
Products
webmin

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-06-24: 3Mentions · 2026-07-01: 1Patch / Workaround · 2026-06-24: 1Patch / Workaround · 2026-07-01: 1Technical Details · 2026-06-24: 3Technical Details · 2026-07-01: 106-2407-01
Signal classification2 categories
Disclosure
375.0%
Patch
125.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-06-243
Disclosure2Patch1
2026-07-011
Disclosure1
Full discourse4 posts
  • iototsecnews@iototsecnews
    Disclosure

    Webmin の深刻な脆弱性群が FIX:認証バイパスや root レベル制御 奪取の可能性 https://iototsecnews.jp/2026/06/24/critical-webmin-vulnerabilities-allow-attackers-to-impersonate-as-any-user/ Webmin の複数モジュールに、認証機能の回避や最高権限の不正奪取を許す一連の脆弱性 CVE-2026-22678/CVE-2026-49102/CVE-2026-49103/CVE-2026-42210 などが見つかりました。この問題の背景には、外部からの入力やセッション制御、ファイルの扱いに関する検証不足があります。これらが悪用されると、一般のユーザーが管理者に成り代わってシステム全般の支配権を握るなど、運用を根底から揺るがす影響が生じ得ます。確実な対策として、速やかな最新版へのアップデートが必要です。その上で、不要な機能を制限しつつ、基本認証の停止など設定の見直しを進めることが大切です。 #CVE202561541 #CVE202567738 #CVE202622678 #CVE202642210 #CVE202649102 #CVE202649103 #CVE202656020 #CVE202656022 #Vulnerability #Webmin

    Post summary

    The post announces the discovery of several serious authentication bypass and privilege escalation flaws in Webmin modules (CVE‑2026‑22678, ‑49102, ‑49103, ‑42210), urges users to apply the latest update and tighten settings, and does not report active exploitation or provide exploit code.

    01000158
    501 followersView on X
  • Cyber Edition@CyberEdition
    Patch

    🚨 Critical Webmin flaw CVE-2026-22678 lets low-privileged users inject stored XSS that can execute in a root admin's browser, potentially leading to full root-level compromise. Webmin 2.641 fixes it. Upgrade immediately. #Webmin #CyberSecurity Read more: https://thecyberedition.com/critical-webmin-stored-xss-vulnerability-lets-untrusted-users-compromise-root-level-access/

    Post summary

    The tweet alerts that a critical XSS flaw (CVE‑2026‑22678) in Webmin lets low‑privileged users inject code potentially leading to root compromise, and it recommends updating to Webmin 2.641 as soon as possible.

    0000160
    739 followersView on X
  • Israel@f1tym1
    Disclosure

    CVE-2026-22678 in Webmin allows untrusted users to inject malicious scripts into notification templates that execute as root, affecting versions before 2.641. https://ift.tt/qWryEw3

    Post summary

    The post announces CVE‑2026‑22678 in Webmin, highlighting that untrusted users can inject scripts into notification templates, causing root‑level execution on versions before 2.641.

    0100050
    1.0K followersView on X
  • sea-are-pea@seaarepea
    Disclosure

    yikes! Yikes! YIKES! Critical Webmin Vulnerabilities Allow Attackers to Impersonate as Any User https://cybersecuritynews.com/webmin-vulnerabilities-impersonate-user/ One of the most critical issues, tracked as CVE-2026-22678, is a stored XSS vulnerability in the System and Server Status module. @sggrc @snubs @hak5 #ITSecurity @jeremyhellstrom @dtnsshow

    Post summary

    The tweet announces a critical Webmin vulnerability (CVE-2026-22678) with a stored XSS in the System and Server Status module and directs readers to a news article, but it does not provide a PoC, exploit, or patch info.

    0000057
    72 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appwebminwebmin---

Explore more