CVE-2026-49103Patch

LOWCVSS 9.4 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Webmin before 2.640 does not safely construct a filename for saving of an attachment within the mailboxes component. This occurs in mailboxes/detachall.cgi.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-24

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-07-01: 1Patch / Workaround · 2026-07-01: 1Technical Details · 2026-07-01: 107-01
Signal classification1 categories
Patch
1100.0%
Referenced assets1 URL
Full discourse1 post
  • iototsecnews@iototsecnews
    Patch

    Webmin の深刻な脆弱性群が FIX:認証バイパスや root レベル制御 奪取の可能性 https://iototsecnews.jp/2026/06/24/critical-webmin-vulnerabilities-allow-attackers-to-impersonate-as-any-user/ Webmin の複数モジュールに、認証機能の回避や最高権限の不正奪取を許す一連の脆弱性 CVE-2026-22678/CVE-2026-49102/CVE-2026-49103/CVE-2026-42210 などが見つかりました。この問題の背景には、外部からの入力やセッション制御、ファイルの扱いに関する検証不足があります。これらが悪用されると、一般のユーザーが管理者に成り代わってシステム全般の支配権を握るなど、運用を根底から揺るがす影響が生じ得ます。確実な対策として、速やかな最新版へのアップデートが必要です。その上で、不要な機能を制限しつつ、基本認証の停止など設定の見直しを進めることが大切です。 #CVE202561541 #CVE202567738 #CVE202622678 #CVE202642210 #CVE202649102 #CVE202649103 #CVE202656020 #CVE202656022 #Vulnerability #Webmin

    Post summary

    Multiple critical Webmin CVEs have been disclosed, exposing authentication bypass and privilege escalation flaws; users are urged to update to the latest version and tighten configuration settings.

    01000158
    501 followersView on X

Explore more