MEDIUM 5.1 NVD
CVE-2026-49243
Webmin is a web-based system administration tool for Unix-like servers. Prior to version 2.650, Webmin users who click on a malicious link to their server are v
Webmin is a web-based system administration tool for Unix-like servers. Prior to version 2.650, Webmin users who click on a malicious link to their server are vulnerable to this XSS vulnerability that could be used to execute attacker-controlled commands. This issue has been patched in version 2.650.
References
- https://github.com/webmin/webmin/commit/2d016751399ed0f4159e72a6cbcd63694a84dabf
- https://github.com/webmin/webmin/releases/tag/2.650
- https://github.com/webmin/webmin/security/advisories/GHSA-hv4w-p8jq-2rp5
This medium severity vulnerability with a CVSS score of 5.1 was published on 2026-09-29 via NVD.
vulnfeed aggregates 10239 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.