CVE-2026-49243: Webmin: Reflected XSS in the Configuration module
Webmin is a web-based system administration tool for Unix-like servers. Prior to version 2.650, Webmin users who click on a malicious link to their server are vulnerable to this XSS vulnerability that could be used to execute attacker-controlled commands. This issue has been patched in version 2.650.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Webminto a version that resolves this vulnerability.Fixed in 2.650
Event History
Frequently Asked Questions
Who is exposed to exploitation?
Webmin users are exposed if they use a version earlier than 2.650 and click a malicious link directed at their Webmin server.
What does an attacker need to exploit this issue?
The attacker needs to induce a Webmin user to click a malicious link to that user's server. The vulnerability is reflected XSS and may be used to execute attacker-controlled commands.
What version fixes the issue?
The issue is patched in Webmin version 2.650. Versions prior to 2.650 are affected according to the advisory.