← Vulnerability feed

Vulnerability record · CVE-2022-0824 · published 2 March 2022

CVE-2022-0824: Webmin improper access control leads to remote code execution

Webmin · Webmin

Webmin before 1.990 contains an improper access control flaw that allows an authenticated user to reach functionality they should not, escalating to remote code execution. Because Webmin is a privileged system administration interface, a successful exploit gives an attacker control of the host it manages.

8.8 CVSS 3.1 High EPSS 97% · top 0.1% CWE-284 · Improper access controlCWE-863 · Incorrect authorization
8.8CVSS 3.1 base score, v2 9.0
97%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
10References, 8 tagged exploit
17 Jun 2026Last modified by NVD

Description

Improper Access Control to Remote Code Execution in GitHub repository webmin/webmin prior to 1.990.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

high priorityThe flaw yields remote code execution on a privileged administration tool with public exploit code and very high EPSS, though it requires valid low-privilege credentials.

What it is

Webmin before 1.990 contains an improper access control flaw that allows an authenticated user to reach functionality they should not, escalating to remote code execution. Because Webmin is a privileged system administration interface, a successful exploit gives an attacker control of the host it manages.

Impact

An attacker with a low-privileged Webmin account can execute arbitrary code on the underlying server, gaining full control of the managed system and its data.

Attack surface

The flaw is reachable over the network through the Webmin web interface; the CVSS vector indicates low privileges are required and no user interaction is needed.

Exploitation

CISA KEV does not list this CVE, but public exploit code is referenced and EPSS is very high (0.96977, 99.9th percentile), indicating active exploitation is likely.

What to do

  • Upgrade Webmin to version 1.990 or later, which contains the patch commit.
  • Restrict network access to the Webmin interface to trusted management networks or VPN only.
  • Audit and minimize Webmin accounts, removing or downgrading unused low-privilege users.
  • Monitor Webmin logs for unexpected file manager or command execution activity.
  • Apply the vendor patch commit if a full upgrade cannot be performed immediately.

Detection

  • Review Webmin access logs for authenticated sessions invoking file manager or command execution endpoints unexpectedly.
  • Alert on new or unusual child processes spawned by the Webmin service account.
  • Monitor for outbound connections from Webmin hosts to unknown external addresses.
  • Correlate Webmin authentication events with subsequent system-level process creation.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-0824 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2019-15107Webmin password_change.cgi command injectionWebmin through 1.920 passes the 'old' parameter in password_change.cgi into a shell command without sanitization, allowing OS command injection. The …KEVEPSS 100%analysed10.0CVE-2005-1177Usermin vulnerabilityUnknown vulnerability in (1) Webmin and (2) Usermin before 1.200 causes Webmin to change permissions and ownership of configuration files, with unkno…EPSS 1.8%10.0CVE-2003-0101Engardelinux guardian digital webtool vulnerabilityminiserv.pl in (1) Webmin before 1.070 and (2) Usermin before 1.000 does not properly handle metacharacters such as line feeds and carriage returns (…EPSS 15%10.0CVE-2002-2201Webmin vulnerabilityThe Printer Administration module for Webmin 0.990 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the …EPSS 3.3%10.0CVE-2001-1196Webmin vulnerabilityDirectory traversal vulnerability in edit_action.cgi of Webmin Directory 0.91 allows attackers to gain privileges via a '..' (dot dot) in the argumen…EPSS 9.8%9.8CVE-2022-36446Webmin apt-lib.pl command injection via unescaped UI commandWebmin before 1.997 fails to HTML-escape a UI command in software/apt-lib.pl, allowing injection of commands through that interface. The flaw is remo…EPSS 96%analysed9.8CVE-2020-35769Webmin vulnerabilityminiserv.pl in Webmin 1.962 on Windows mishandles special characters in query arguments to the CGI program.EPSS 1.8%9.8CVE-2018-8712Webmin path traversal vulnerabilityAn issue was discovered in Webmin 1.840 and 1.880 when the default Yes setting of "Can view any file as a log file" is enabled. As a result of weak d…EPSS 1.8%

Source: NIST National Vulnerability Database (record CVE-2022-0824), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.