CVE-2026-56020 Details
Description
The Webmin HTTP server (miniserv.pl) allows unauthenticated attackers to impersonate any user with a configured SSL client certificate by sending a forged HTTP header. A remote attacker can spoof certificate DNs and authenticate as any user. Fixed in 2.202.
A vulnerability in the Webmin HTTP server (miniserv.pl) allows unauthenticated attackers to impersonate users with SSL client certificates by sending forged HTTP headers. This spoofing can be used to authenticate as any user by manipulating certificate distinguished names. The issue has been fixed in Webmin version 2.641.
Users are advised to upgrade to Webmin version 2.641 or later.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jun 19, 2026CISA-ADP
Assessed May 29, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/webmin/webmin/releases/tag/2.202 | Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government | |
| https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-169-02.json | Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government | |
| https://webmin.com/security/#webmin-prior-to-2202 | Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government | |
| https://www.cve.org/CVERecord?id=CVE-2026-56020 | Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-290 | Authentication Bypass by Spoofing | Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government |
Affected Products
No affected product data is available for this CVE.
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 11, 2026 | CVE Modified | Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government |
| Jun 22, 2026 | CVE Modified | CISA-ADP |
| Jun 19, 2026 | CVE Modified | CISA-ADP |
| Jun 18, 2026 | New CVE Received | Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government |