CVE-2026-56020: Webmin HTTP header authentication bypass
The Webmin HTTP server (miniserv.pl) allows unauthenticated attackers to impersonate any user with a configured SSL client certificate by sending a forged HTTP header. A remote attacker can spoof certificate DNs and authenticate as any user. Fixed in 2.641.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Webmin HTTP server (miniserv.pl)to a version that resolves this vulnerability.Fixed in 2.641
Event History
Frequently Asked Questions
What is the severity of CVE-2026-56020?
CVE-2026-56020 has a severity rating of 8.1, which is classified as high.
How do I fix CVE-2026-56020?
To fix CVE-2026-56020, upgrade your Webmin software to version 2.641 or later.
What type of attack does CVE-2026-56020 enable?
CVE-2026-56020 enables unauthenticated attackers to impersonate any user by sending a forged HTTP header.
What impact does CVE-2026-56020 have on Webmin?
CVE-2026-56020 allows attackers to spoof certificate DNs, potentially gaining unauthorized access to user accounts.
Is CVE-2026-56020 applicable to all versions of Webmin?
CVE-2026-56020 is applicable to versions of Webmin prior to 2.641.