CVE-2026-56022: Webmin MFA bypass
Webmin accepts basic authentication without session cookies when an attacker provides the 'User-Agent: webmin' header, allowing bypass of additional MFA requirements. Fixed in 2.641.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Webminto a version that resolves this vulnerability.Fixed in 2.641
Event History
Frequently Asked Questions
What is the severity of CVE-2026-56022?
The severity of CVE-2026-56022 is medium with a base score of 5.3.
What does CVE-2026-56022 exploit?
CVE-2026-56022 exploits the Webmin by allowing MFA to be bypassed through basic authentication when the 'User-Agent: webmin' header is supplied.
How do I fix CVE-2026-56022?
To fix CVE-2026-56022, update Webmin to version 2.641 or later.
What are the consequences of CVE-2026-56022?
The consequence of CVE-2026-56022 is that it allows unauthorized access by bypassing multi-factor authentication.
Which versions of Webmin are affected by CVE-2026-56022?
CVE-2026-56022 affects all versions of Webmin prior to 2.641.