๐Ÿ” CVE Alert

CVE-2026-42210

UNKNOWN 0.0

Webmin 2FA requirement bypass

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Webmin is a web-based system administration tool for Unix-like servers. Prior to version 2.640, for Webmin accounts that require a second authentication factor (typically TOTP), an attacker with knowledge of the username and password can bypass the 2FA requirement by using Basic authentication. Webmin is a web-based system administration tool for Unix-like servers. As a workaround, apply the patch from commit da18a16c84ae5c0b78cad79609cb0efb174000ec manually.

CWE CWE-287
Vendor webmin
Product webmin
Published Jul 20, 2026
Last Updated Jul 20, 2026
Stay Ahead of the Next One

Get instant alerts for webmin webmin

Be the first to know when new unknown vulnerabilities affecting webmin webmin are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

webmin / webmin
< 2.640

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/webmin/webmin/security/advisories/GHSA-qpww-fff2-6fgv github.com: https://github.com/webmin/webmin/commit/da18a16c84ae5c0b78cad79609cb0efb174000ec