By weakness (CWE)
CWE-777: related vulnerabilities
CVEs classified under CWE-777. Understanding the weakness class helps prioritize systemic fixes over one-off patches.
1 published vulnerability
- CVE-2026-56021MEDIUM 5.3
Webmin contains a flaw that allows anyone on the network to read sensitive configuration files without logging in. The vulnerability bypasses a validation filter that's supposed to block access to .conf files in module directories. An attacker can exploit this to extract configuration data that may contain credentials, API keys, or other sensitive information. This is a straightforward information disclosure issue with moderate severity.