Vulnerability record · CVE-2022-0824 · published 2 March 2022
CVE-2022-0824: Webmin improper access control leads to remote code execution
Webmin · Webmin
Webmin before 1.990 contains an improper access control flaw that allows an authenticated user to reach functionality they should not, escalating to remote code execution. Because Webmin is a privileged system administration interface, a successful exploit gives an attacker control of the host it manages.
Description
Improper Access Control to Remote Code Execution in GitHub repository webmin/webmin prior to 1.990.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityThe flaw yields remote code execution on a privileged administration tool with public exploit code and very high EPSS, though it requires valid low-privilege credentials.
What it is
Webmin before 1.990 contains an improper access control flaw that allows an authenticated user to reach functionality they should not, escalating to remote code execution. Because Webmin is a privileged system administration interface, a successful exploit gives an attacker control of the host it manages.
Impact
An attacker with a low-privileged Webmin account can execute arbitrary code on the underlying server, gaining full control of the managed system and its data.
Attack surface
The flaw is reachable over the network through the Webmin web interface; the CVSS vector indicates low privileges are required and no user interaction is needed.
Exploitation
CISA KEV does not list this CVE, but public exploit code is referenced and EPSS is very high (0.96977, 99.9th percentile), indicating active exploitation is likely.
What to do
- Upgrade Webmin to version 1.990 or later, which contains the patch commit.
- Restrict network access to the Webmin interface to trusted management networks or VPN only.
- Audit and minimize Webmin accounts, removing or downgrading unused low-privilege users.
- Monitor Webmin logs for unexpected file manager or command execution activity.
- Apply the vendor patch commit if a full upgrade cannot be performed immediately.
Detection
- Review Webmin access logs for authenticated sessions invoking file manager or command execution endpoints unexpectedly.
- Alert on new or unusual child processes spawned by the Webmin service account.
- Monitor for outbound connections from Webmin hosts to unknown external addresses.
- Correlate Webmin authentication events with subsequent system-level process creation.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2022-0824 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-0824), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.