Vulnerability Description
Webmin before 2.640 allows mailboxes/detach.cgi XSS via an SVG document attachment that is viewed in the mailboxes component, because image/svg+xml is used instead of a safe type (e.g., text/plain).
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
- https://github.com/webmin/webmin/commit/cf432879a14568c4bb44cd2f9e5a9bd0e168edc1
- https://github.com/webmin/webmin/compare/2.630...2.640
FAQ
What is CVE-2026-49102?
CVE-2026-49102 is a vulnerability with a CVSS score of 6.1 (MEDIUM). Webmin before 2.640 allows mailboxes/detach.cgi XSS via an SVG document attachment that is viewed in the mailboxes component, because image/svg+xml is used instead of a safe type (e.g., text/plain).
How severe is CVE-2026-49102?
CVE-2026-49102 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-49102?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.