CVE-2026-49102: XSS
Published May 27, 2026
·Updated
Webmin before 2.640 allows mailboxes/detach.cgi XSS via an SVG document attachment that is viewed in the mailboxes component, because image/svg+xml is used instead of a safe type (e.g., text/plain).
Affected Software
1 affected component
Webmin Webmin<2.640
Event History
May 27, 2026
CVE Published
via MITRE·02:31 PM
Data Sourced
via MITRE·02:31 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-49102?
The severity of CVE-2026-49102 is medium with a CVSS score of 6.1.
2
What type of vulnerability is CVE-2026-49102?
CVE-2026-49102 is a Cross-Site Scripting (XSS) vulnerability.
3
How do I fix CVE-2026-49102?
To fix CVE-2026-49102, upgrade Webmin to version 2.640 or higher.
4
What components are affected by CVE-2026-49102?
CVE-2026-49102 affects the mailboxes component of Webmin.
5
How is CVE-2026-49102 exploited?
CVE-2026-49102 can be exploited via an SVG document attachment in mailboxes viewed with improper content type handling.