CVE-2026-49102Patch

LOWCVSS 6.1 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Webmin before 2.640 allows mailboxes/detach.cgi XSS via an SVG document attachment that is viewed in the mailboxes component, because image/svg+xml is used instead of a safe type (e.g., text/plain).

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-07-01: 1Patch / Workaround · 2026-07-01: 1Technical Details · 2026-07-01: 107-01
Signal classification1 categories
Patch
1100.0%
Referenced assets1 URL
Full discourse1 post
  • iototsecnews@iototsecnews
    Patch

    Webmin の深刻な脆弱性群が FIX:認証バイパスや root レベル制御 奪取の可能性 https://iototsecnews.jp/2026/06/24/critical-webmin-vulnerabilities-allow-attackers-to-impersonate-as-any-user/ Webmin の複数モジュールに、認証機能の回避や最高権限の不正奪取を許す一連の脆弱性 CVE-2026-22678/CVE-2026-49102/CVE-2026-49103/CVE-2026-42210 などが見つかりました。この問題の背景には、外部からの入力やセッション制御、ファイルの扱いに関する検証不足があります。これらが悪用されると、一般のユーザーが管理者に成り代わってシステム全般の支配権を握るなど、運用を根底から揺るがす影響が生じ得ます。確実な対策として、速やかな最新版へのアップデートが必要です。その上で、不要な機能を制限しつつ、基本認証の停止など設定の見直しを進めることが大切です。 #CVE202561541 #CVE202567738 #CVE202622678 #CVE202642210 #CVE202649102 #CVE202649103 #CVE202656020 #CVE202656022 #Vulnerability #Webmin

    Post summary

    The article highlights multiple critical Webmin CVEs that allow authentication bypass and privilege escalation, urging users to immediately apply the latest patch and tighten configuration settings.

    01000158
    501 followersView on X

Explore more