Vulnerability Description
Webmin is a web-based system administration tool for Unix-like servers. Prior to version 2.640, for Webmin accounts that require a second authentication factor (typically TOTP), an attacker with knowledge of the username and password can bypass the 2FA requirement by using Basic authentication. Webmin is a web-based system administration tool for Unix-like servers. As a workaround, apply the patch from commit da18a16c84ae5c0b78cad79609cb0efb174000ec manually.
Related Weaknesses (CWE)
References
- https://github.com/webmin/webmin/commit/da18a16c84ae5c0b78cad79609cb0efb174000ec
- https://github.com/webmin/webmin/security/advisories/GHSA-qpww-fff2-6fgv
FAQ
What is CVE-2026-42210?
CVE-2026-42210 is a documented vulnerability. Webmin is a web-based system administration tool for Unix-like servers. Prior to version 2.640, for Webmin accounts that require a second authentication factor (typically TOTP), an attacker with knowl...
How severe is CVE-2026-42210?
CVSS scoring is not yet available for CVE-2026-42210. Check NVD for updates.
Is there a patch for CVE-2026-42210?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.