Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 27 May 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Unsafely Constructed Filename in Webmin Mailbox Attachment Saving Leads to Remote Code Execution |
Wed, 27 May 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 27 May 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Webmin before 2.640 does not safely construct a filename for saving of an attachment within the mailboxes component. This occurs in mailboxes/detachall.cgi. | |
| First Time appeared |
Webmin
Webmin webmin |
|
| Weaknesses | CWE-24 | |
| CPEs | cpe:2.3:a:webmin:webmin:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Webmin
Webmin webmin |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-05-27T16:14:12.073Z
Reserved: 2026-05-27T14:37:18.174Z
Link: CVE-2026-49103
Updated: 2026-05-27T16:14:09.539Z
Status : Deferred
Published: 2026-05-27T15:16:34.170
Modified: 2026-06-17T10:55:30.553
Link: CVE-2026-49103
No data.
OpenCVE Enrichment
Updated: 2026-05-28T04:45:07Z