SB2026080121 - Server-Side Request Forgery (SSRF) in Webmin



SB2026080121 - Server-Side Request Forgery (SSRF) in Webmin

Published: August 1, 2026

Security Bulletin ID SB2026080121
CSH Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Information disclosure

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Server-Side Request Forgery (SSRF) (CVE-ID: N/A)

CWE-ID: CWE-918 - Server-Side Request Forgery (SSRF)

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear


The vulnerability allows a remote user to access internal network resources and cloud metadata endpoints.

The vulnerability exists due to server-side request forgery (SSRF) in the Upload and Download and File Manager modules when downloading files from user-supplied URLs. A remote user can supply a crafted URL to access internal network resources and cloud metadata endpoints.

Only untrusted users with access to modules that can download files from other URLs are affected, and accessible targets must not be protected by authentication.


Remediation

Install update from vendor's website.