A newly disclosed vulnerability in Webmin’s HTTP server component, miniserv.pl, allows an unauthenticated remote attacker to impersonate any user configured with an SSL client certificate by sending a forged HTTP header and spoofing certificate distinguished names (DNs). The issue is tracked as CVE-2026-56020, classified as CWE-290: Authentication Bypass by Spoofing, and is rated 8.1 HIGH under CVSS v3.1 and 9.2 CRITICAL under CVSS v4.0.
The flaw affects Webmin versions before 2.641, and version 2.641 contains the fix. Public advisories recommend upgrading to 2.641 or later and verifying that SSL client certificate validation is correctly configured. The CVE record credits Adem El Adeb of vulone.com/vul1.com for reporting the issue.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
On 2026-06-18, CVE-2026-56020 was published describing a spoofing-based authentication bypass in Webmin's miniserv.pl HTTP server component. The flaw was rated 8.1 under CVSS v3.1 and 9.2 under CVSS v4.0, with credit given to Adem El Adeb.
Webmin version 2.641 was identified as containing the fix for an authentication bypass flaw in miniserv.pl that could let an unauthenticated attacker impersonate users with configured SSL client certificates. Versions before 2.641 are affected.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.