CVE-2026-56020
The Webmin HTTP server (miniserv.pl) allows unauthenticated attackers to impersonate any user with a configured SSL client certificate by sending a forged HTTP header. A remote attacker can spoof certificate DNs and authenticate as any user. Fixed in 2.202.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-169-02.json, https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/56xxx/CVE-2026-56020.json, https://github.com/webmin/webmin/releases/tag/2.202, https://nvd.nist.gov/vuln/detail/CVE-2026-56020, https://webmin.com/security/#webmin-prior-to-2202, https://www.cve.org/CVERecord?id=CVE-2026-56020