
🚨 CRITICAL - Webmin http://miniserv.pl forged header enables SSL client cert user impersonation (CVE-2026-56020) Webmin’s built-in HTTP server (http://miniserv.pl) improperly trusts a client-supplied HTTP header for SSL client certificate identity, allowing unauthenticated attackers to spoof certificate distinguished names (DNs). By sending a forged header, an attacker can impersonate any user that has an SSL client certificate configured without presenting a valid certificate. This is a remote authentication bypass rooted in broken trust boundaries between the TLS layer and application logic. Real-world impact includes full takeover of Webmin accounts, administrative access, and downstream compromise of managed systems. 👉 Affected: Webmin < 2.641 | Upgrade to 2.641
Post summary
Webmin’s HTTP server flaw allows unauthenticated attackers to spoof SSL client certificates and impersonate users; patch available by upgrading to version 2.641.
