CVE-2026-49243
Webmin is a web-based system administration tool for Unix-like servers. Prior to version 2.650, Webmin users who click on a malicious link to their server are vulnerable to this XSS vulnerability that could be used to execute attacker-controlled commands. This issue has been patched in version 2.650.
- Published Sep 29, 2026
- CVSS 5.1 medium
- 0.3% chance of exploitation in the next 30 days (EPSS)
- A fix is available