← Vulnerability feed

Vulnerability record · CVE-2022-36446 · published 25 July 2022

CVE-2022-36446: Webmin apt-lib.pl command injection via unescaped UI command

Webmin · Webmin

Webmin before 1.997 fails to HTML-escape a UI command in software/apt-lib.pl, allowing injection of commands through that interface. The flaw is remotely reachable with no authentication or user interaction per the CVSS vector, and public exploit code exists, making it a serious risk for exposed Webmin instances.

9.8 CVSS 3.1 Critical EPSS 96% · top 0.1% CWE-116 · CWE-116
9.8CVSS 3.1 base score
96%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
12References, 4 tagged exploit
17 Jun 2026Last modified by NVD

Description

software/apt-lib.pl in Webmin before 1.997 lacks HTML escaping for a UI command.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

critical priorityCVSS 9.8 with no authentication or interaction required, public exploit code, and a very high EPSS score make this an urgent patch target.

What it is

Webmin before 1.997 fails to HTML-escape a UI command in software/apt-lib.pl, allowing injection of commands through that interface. The flaw is remotely reachable with no authentication or user interaction per the CVSS vector, and public exploit code exists, making it a serious risk for exposed Webmin instances.

Impact

An attacker can execute arbitrary commands on the Webmin host, gaining full control of the server and any data or credentials it holds.

Attack surface

Reached over the network via the Webmin web interface; the CVSS vector indicates no authentication and no user interaction are required.

Exploitation

Not listed in CISA KEV, but EPSS is very high (0.96, 99.9th percentile) and multiple references are tagged Exploit, including Packet Storm and Exploit-DB entries, so working public exploits are available.

What to do

  • Upgrade Webmin to 1.997 or later, which contains the patch commit 13f7bf9621a82d93f1e9dbd838d1e22020221bde.
  • If immediate upgrade is not possible, restrict network access to the Webmin interface to trusted management hosts only.
  • Disable or remove the affected package-updates/apt module if it is not needed.
  • Audit Webmin accounts and rotate credentials for any host that ran a vulnerable version while exposed.

Detection

  • Review Webmin access logs for requests to the apt/package-updates module from unexpected source IPs.
  • Monitor for command execution or child processes spawned by the Webmin service (for example shell or apt commands) outside normal update windows.
  • Check for unexpected files, cron entries, or new accounts on Webmin hosts as post-exploitation indicators.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-36446 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2019-15107Webmin password_change.cgi command injectionWebmin through 1.920 passes the 'old' parameter in password_change.cgi into a shell command without sanitization, allowing OS command injection. The …KEVEPSS 100%analysed10.0CVE-2005-1177Usermin vulnerabilityUnknown vulnerability in (1) Webmin and (2) Usermin before 1.200 causes Webmin to change permissions and ownership of configuration files, with unkno…EPSS 1.8%10.0CVE-2003-0101Engardelinux guardian digital webtool vulnerabilityminiserv.pl in (1) Webmin before 1.070 and (2) Usermin before 1.000 does not properly handle metacharacters such as line feeds and carriage returns (…EPSS 15%10.0CVE-2002-2201Webmin vulnerabilityThe Printer Administration module for Webmin 0.990 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the …EPSS 3.3%10.0CVE-2001-1196Webmin vulnerabilityDirectory traversal vulnerability in edit_action.cgi of Webmin Directory 0.91 allows attackers to gain privileges via a '..' (dot dot) in the argumen…EPSS 9.8%9.8CVE-2020-35769Webmin vulnerabilityminiserv.pl in Webmin 1.962 on Windows mishandles special characters in query arguments to the CGI program.EPSS 1.8%9.8CVE-2018-8712Webmin path traversal vulnerabilityAn issue was discovered in Webmin 1.840 and 1.880 when the default Yes setting of "Can view any file as a log file" is enabled. As a result of weak d…EPSS 1.8%9.6CVE-2021-32157Webmin cross-site scripting vulnerabilityA Cross-Site Scripting (XSS) vulnerability exists in Webmin 1.973 via the Scheduled Cron Jobs feature.EPSS 4.0%

Source: NIST National Vulnerability Database (record CVE-2022-36446), CISA KEV, FIRST EPSS (scores of 2026-09-25). This page is refreshed as NVD updates the record.