CVE-2026-56022
Webmin accepts basic authentication without session cookies when an attacker provides the 'User-Agent: webmin' header, allowing bypass of ad
CVSS
5.3
Medio
EPSS
0.6%
p44
KEV
—
Exploit Today
13
0-100
Publicado: 18 jun 2026 · Última mod.: 11 ago 2026 · CWE-308
0.5%EPSS · 30 días0.6%
2026-08-072026-09-04
Webmin accepts basic authentication without session cookies when an attacker provides the 'User-Agent: webmin' header, allowing bypass of additional MFA requirements. Fixed in 2.640.
- github.comhttps://github.com/webmin/webmin/releases/tag/2.640
- raw.githubusercontent.comhttps://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-169-02.json
- webmin.comhttps://webmin.com/security/#webmin-prior-to-2640
- www.cve.orghttps://www.cve.org/CVERecord?id=CVE-2026-56022
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-85590——
——0phpMyFAQ before 4.1.8 contains an authentication bypass vulnerability in its two-factor authentication (TOTP) disable functionality. The removeTwofactorConfig() handler (reachable via POST /api/user/remove-twofactor) verifies only that the user is logged in and that a valid CSRF token is supplied, then disables TOTP without requiring password re-entry or a current TOTP code. The same downgrade is also reachable inline via PUT /api/user/data/update, which accepts a plain twofactor_enabled form field under the same session+CSRF-only guard. An attacker who has hijacked a user's session can silently strip two-factor protection from any account, including administrator accounts, after which password-only authentication succeeds.1dCVE-2026-676118.1 ALT42.8%
——13OpenEMR through 8.2.0 contains an authentication bypass vulnerability that allows attackers with valid credentials to circumvent multi-factor authentication by exploiting the exposed OAuth2 password grant flow through an unauthenticated client registration endpoint. Attackers can register an OAuth2 client via the unauthenticated registration endpoint and use the password grant to exchange credentials for an API access token, bypassing the normal web interface authentication and any enforced multi-factor authentication controls.4dCVE-2026-156169.1 CRÍ25.5%
——8Logto does not enforce locally configured MFA during SSO authentication, allowing users to bypass second-factor requirements and grants unauthorized access.40d