CVE-2026-56022 Details
Description
Webmin accepts basic authentication without session cookies when an attacker provides the 'User-Agent: webmin' header, allowing bypass of additional MFA requirements. Fixed in 2.640.
A vulnerability in Webmin allows for bypassing multi-factor authentication (MFA) requirements. This issue arises because Webmin accepts basic authentication without session cookies, provided the 'User-Agent: webmin' header is included. The vulnerability is present in Webmin versions prior to 2.641.
Users are advised to upgrade to Webmin version 2.641 or later.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jun 24, 2026CISA-ADP
Assessed May 29, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/webmin/webmin/releases/tag/2.640 | Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government | Release Notes |
| https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-169-02.json | Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government | VDB Entry |
| https://webmin.com/security/#webmin-prior-to-2640 | Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government | Vendor Advisory |
| https://www.cve.org/CVERecord?id=CVE-2026-56022 | Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government | VDB Entry |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-308 | Use of Single-factor Authentication | Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government |
Affected Products
| Product | Versions |
|---|---|
| webmin webmin | < 2.640 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 11, 2026 | Initial Analysis | [email protected] |
| Aug 11, 2026 | CVE Modified | Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government |
| Jun 24, 2026 | CVE Modified | CISA-ADP |
| Jun 18, 2026 | New CVE Received | Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government |