CVE-2026-42210Patch

LOWCVSS 5.3 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Webmin is a web-based system administration tool for Unix-like servers. Prior to version 2.640, for Webmin accounts that require a second authentication factor (typically TOTP), an attacker with knowledge of the username and password can bypass the 2FA requirement by using Basic authentication. Webmin is a web-based system administration tool for Unix-like servers. As a workaround, apply the patch from commit da18a16c84ae5c0b78cad79609cb0efb174000ec manually.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-287

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-07-01: 1Patch / Workaround · 2026-07-01: 1Technical Details · 2026-07-01: 107-01
Signal classification1 categories
Patch
1100.0%
Referenced assets1 URL
Full discourse1 post
  • iototsecnews@iototsecnews
    Patch

    Webmin の深刻な脆弱性群が FIX:認証バイパスや root レベル制御 奪取の可能性 https://iototsecnews.jp/2026/06/24/critical-webmin-vulnerabilities-allow-attackers-to-impersonate-as-any-user/ Webmin の複数モジュールに、認証機能の回避や最高権限の不正奪取を許す一連の脆弱性 CVE-2026-22678/CVE-2026-49102/CVE-2026-49103/CVE-2026-42210 などが見つかりました。この問題の背景には、外部からの入力やセッション制御、ファイルの扱いに関する検証不足があります。これらが悪用されると、一般のユーザーが管理者に成り代わってシステム全般の支配権を握るなど、運用を根底から揺るがす影響が生じ得ます。確実な対策として、速やかな最新版へのアップデートが必要です。その上で、不要な機能を制限しつつ、基本認証の停止など設定の見直しを進めることが大切です。 #CVE202561541 #CVE202567738 #CVE202622678 #CVE202642210 #CVE202649102 #CVE202649103 #CVE202656020 #CVE202656022 #Vulnerability #Webmin

    Post summary

    The text announces several CVEs affecting Webmin modules, highlights authentication bypass and privilege escalation issues, and urges users to urgently update to the latest version and adjust settings to mitigate the risk.

    01000158
    501 followersView on X

Explore more