CVE-2026-49103
Webmin before 2.640 does not safely construct a filename for saving of an attachment within the mailboxes component. This occurs in mailboxes/detachall.cgi.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 9.4
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
- EPSS probability
- 0.40%
- CWE
- CWE-24
- Published
- 2026-05-27
- Last modified
- 2026-05-27
Affected products
- Webmin Webmin
Weakness type
Related vulnerabilities
- CVE-2026-14947 — Frauscher Sensortechnik: FDS102 for FAdC/FAdCi R2 is vulnerable to Remote Code Execution via malicious ZIP file
- CVE-2026-76353 — Path Traversal through Knowledge Bundle Replication in Splunk Enterprise
- CVE-2026-73573 — In Zimbra Collaboration (ZCS) before 10.1.17, a path traversal vulnerability exists in the Zimbra...
- CVE-2026-48047 — XWiki Platform vulnerable to potential arbitrary file writing using path traversal from (subwiki) admin
- CVE-2026-66140 — Exim before 4.99.5 allows directory traversal to access files outside of the spool area, and...
- CVE-2026-46687 — Emlog Local File Inclusion (LFI)
- CVE-2026-44942 — libzypp .repo files can have an optional path which can lead to path traversal attacks
- CVE-2026-22810 — Joplin: Path traversal in OneNote importer allows overwriting arbitrary files