CVE-2026-22678: Webmin < 2.641 Stored XSS via System and Server Status
Webmin before 2.641 contains a stored cross-site scripting vulnerability in the email template description field of the System and Server Status module that allows low-privileged authenticated attackers to execute arbitrary JavaScript in the browser context of administrators by injecting unsanitized input stored in savetmpl.cgi and rendered unescaped in listtmpls.cgi.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-22678?
The severity of CVE-2026-22678 is medium, rated at 5.1.
How do I fix CVE-2026-22678?
To fix CVE-2026-22678, upgrade Webmin to version 2.641 or later.
What type of vulnerability is CVE-2026-22678?
CVE-2026-22678 is a stored cross-site scripting (XSS) vulnerability.
Who is affected by CVE-2026-22678?
Low-privileged authenticated attackers can exploit CVE-2026-22678 to execute arbitrary commands.
What component of Webmin is vulnerable in CVE-2026-22678?
The vulnerability in CVE-2026-22678 affects the email template description field of the System and Server Status module.