CVE-2026-56021 Details
Description
Webmin allows unauthenticated attackers to read the contents of any file ending in .conf within module directories, due to a bypassable regex pattern.
A vulnerability in Webmin prior to version 2.641 allows unauthenticated attackers to read any file ending in .conf within module directories. This issue arises from a regex pattern that can be bypassed, leading to unauthorized access to sensitive configuration files.
Users are advised to upgrade to Webmin version 2.641 or later.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jun 24, 2026CISA-ADP
Assessed May 29, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/webmin/webmin/releases/tag/2.641 | Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government | ProductRelease Notes |
| https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-169-02.json | Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government | VDB Entry |
| https://webmin.com/security/#webmin-prior-to-2641 | Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government | Vendor Advisory |
| https://www.cve.org/CVERecord?id=CVE-2026-56021 | Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government | VDB Entry |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-185 | Incorrect Regular Expression | Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government |
| CWE-777 | Regular Expression without Anchors | Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government |
Affected Products
| Product | Versions |
|---|---|
| webmin webmin | < 1.290 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 11, 2026 | Initial Analysis | [email protected] |
| Jun 24, 2026 | CVE Modified | CISA-ADP |
| Jun 18, 2026 | New CVE Received | Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government |