Vulnerability Description
Webmin before 2.640 does not safely construct a filename for saving of an attachment within the mailboxes component. This occurs in mailboxes/detachall.cgi.
Related Weaknesses (CWE)
References
- https://github.com/webmin/webmin/commit/cf432879a14568c4bb44cd2f9e5a9bd0e168edc1
- https://github.com/webmin/webmin/compare/2.630...2.640
FAQ
What is CVE-2026-49103?
CVE-2026-49103 is a documented vulnerability. Webmin before 2.640 does not safely construct a filename for saving of an attachment within the mailboxes component. This occurs in mailboxes/detachall.cgi.
How severe is CVE-2026-49103?
CVSS scoring is not yet available for CVE-2026-49103. Check NVD for updates.
Is there a patch for CVE-2026-49103?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.