CVE-2026-49103
Webmin before 2.640 does not safely construct a filename for saving of an attachment within the mailboxes component. This occurs in mailboxes/detachall.cgi.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://github.com/webmin/webmin/compare/2.630...2.640, https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/49xxx/CVE-2026-49103.json, https://nvd.nist.gov/vuln/detail/CVE-2026-49103, https://github.com/webmin/webmin/commit/cf432879a14568c4bb44cd2f9e5a9bd0e168edc1