
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-56020 is an authentication bypass vulnerability in the Webmin HTTP server (miniserv.pl) that allows unauthenticated remote attackers to impersonate any user with a configured SSL client certificate by sending a forged HTTP header. The vulnerability affects all Webmin versions prior to 2.641 and was disclosed on June 18, 2026. It carries a CVSS v3.1 base score of 8.1 (High) and a CVSS v4.0 base score of 9.2 (Critical) (Github Advisory, Webmin Release).
The root cause is classified as CWE-290 (Authentication Bypass by Spoofing): miniserv.pl trusts a client-supplied HTTP header to convey the SSL client certificate Distinguished Name (DN) without adequately verifying that the header originates from a legitimate, verified TLS handshake. An unauthenticated attacker can craft an HTTP request containing a forged header that mimics the DN of any user configured to authenticate via SSL client certificates, causing Webmin to grant access as that user. The attack requires no privileges and no user interaction, though it does require that the target Webmin instance has SSL client certificate authentication configured (Attack Requirements: Present in CVSS v4.0) (Github Advisory).
Successful exploitation allows a remote, unauthenticated attacker to fully impersonate any Webmin user — including administrative accounts — and perform any action that user is authorized to execute, such as system configuration changes, command execution, and file management. This results in high confidentiality, integrity, and availability impact on the affected system. Because Webmin is commonly used to administer Linux/Unix servers, a compromised administrative account could enable full root-level system takeover and lateral movement within the managed infrastructure (Github Advisory).
As of the time of disclosure, there is no public proof-of-concept exploit and no confirmed in-the-wild exploitation (Github Advisory). The EPSS score is approximately 0.285%, placing it in the 20th percentile for exploitation likelihood within 30 days. The vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. NVD SSVC assessment also indicates no known exploitation at this time.
SSL_CLIENT_S_DN or similar) containing the spoofed DN of the target user.SSL_CLIENT_S_DN, X-SSL-Client-DN, or similar) from IP addresses not associated with known certificate holders; requests authenticating as privileged users from IPs without a corresponding TLS client certificate exchange./var/webmin/miniserv.log) showing successful logins for administrative users from unexpected source IPs or at unusual times; authentication events lacking a corresponding TLS handshake record in the web server SSL logs.The primary remediation is to upgrade Webmin to version 2.641 or later, which introduces support for trusted proxy IP addresses and addresses the header spoofing issue (Webmin Release). As a workaround prior to patching, administrators should restrict SSL client certificate-based authentication to trusted internal networks using firewall rules, and avoid exposing Webmin directly to the internet. Additionally, monitoring authentication logs for anomalous certificate DN usage is recommended (Github Advisory).
Coverage of CVE-2026-56020 appeared across several security news outlets shortly after disclosure, including CyberSecurityNews and The Daily Tech Feed, which highlighted the user impersonation risk (CyberSecurityNews, DailyTechFeed). VPNcentral noted that Webmin 2.641 also addresses 2FA bypass issues alongside this vulnerability (VPNcentral). SecurityOnline.info and Hawk-Eye's weekly threat digest also included the vulnerability in their roundups, reflecting moderate community interest given Webmin's widespread use in Linux server administration.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."