CVE-2026-49243
Deferred Deferred - Pending Action

Cross-Site Scripting (XSS) in Webmin Prior to 2.650

Vulnerability report for CVE-2026-49243, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-29

Last updated on: 2026-09-29

Assigner: GitHub, Inc.

Description

Webmin is a web-based system administration tool for Unix-like servers. Prior to version 2.650, Webmin users who click on a malicious link to their server are vulnerable to this XSS vulnerability that could be used to execute attacker-controlled commands. This issue has been patched in version 2.650.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-29
Last Modified
2026-09-29
Generated
2026-09-29
AI Q&A
2026-09-29
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
webmin webmin to 2.650 (exc)
webmin webmin to 2.642 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-79 The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a reflected cross-site scripting (XSS) vulnerability in Webmin, a web-based system administration tool for Unix-like servers. It allows attackers to execute malicious commands on a server by tricking users into clicking a harmful link. The issue affects versions prior to 2.650 and has been patched in version 2.650.

Detection Guidance

To detect this reflected XSS vulnerability in Webmin, check the version of Webmin installed on your system. Run: webmin --version or check the Webmin interface version. If the version is below 2.642, the system is vulnerable. Additionally, monitor network traffic for suspicious links or requests targeting Webmin status messages.

Impact Analysis

An attacker could use this vulnerability to run unauthorized commands on your server if you click a malicious link. This could lead to data theft, unauthorized access, or further compromise of your system. The impact depends on the server's configuration and the permissions of the Webmin user.

Mitigation Strategies

Immediately update Webmin to version 2.642 or later. If updating is not possible, apply the patch provided by Emiliano Versini. Disable unnecessary Webmin modules and restrict access to the Webmin interface via firewall rules. Monitor for unusual activity or unauthorized commands.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-49243. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart