Server-Side Request Forgery (SSRF) in Webmin - #VU140703

 

Server-Side Request Forgery (SSRF) in Webmin - #VU140703

Published: August 1, 2026


Vulnerability identifier: #VU140703
CSH Severity: Low
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: N/A
CWE-ID: CWE-918
Exploitation vector: Remote access
Exploit availability: No public exploit available
Affected software:
Webmin

Detailed vulnerability description

The vulnerability allows a remote user to access internal network resources and cloud metadata endpoints.

The vulnerability exists due to server-side request forgery (SSRF) in the Upload and Download and File Manager modules when downloading files from user-supplied URLs. A remote user can supply a crafted URL to access internal network resources and cloud metadata endpoints.

Only untrusted users with access to modules that can download files from other URLs are affected, and accessible targets must not be protected by authentication.


Remediation

Install security update from vendor's website.

Sources