Vulnerability record · CVE-2022-36446 · published 25 July 2022
CVE-2022-36446: Webmin apt-lib.pl command injection via unescaped UI command
Webmin · Webmin
Webmin before 1.997 fails to HTML-escape a UI command in software/apt-lib.pl, allowing injection of commands through that interface. The flaw is remotely reachable with no authentication or user interaction per the CVSS vector, and public exploit code exists, making it a serious risk for exposed Webmin instances.
Description
software/apt-lib.pl in Webmin before 1.997 lacks HTML escaping for a UI command.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with no authentication or interaction required, public exploit code, and a very high EPSS score make this an urgent patch target.
What it is
Webmin before 1.997 fails to HTML-escape a UI command in software/apt-lib.pl, allowing injection of commands through that interface. The flaw is remotely reachable with no authentication or user interaction per the CVSS vector, and public exploit code exists, making it a serious risk for exposed Webmin instances.
Impact
An attacker can execute arbitrary commands on the Webmin host, gaining full control of the server and any data or credentials it holds.
Attack surface
Reached over the network via the Webmin web interface; the CVSS vector indicates no authentication and no user interaction are required.
Exploitation
Not listed in CISA KEV, but EPSS is very high (0.96, 99.9th percentile) and multiple references are tagged Exploit, including Packet Storm and Exploit-DB entries, so working public exploits are available.
What to do
- Upgrade Webmin to 1.997 or later, which contains the patch commit 13f7bf9621a82d93f1e9dbd838d1e22020221bde.
- If immediate upgrade is not possible, restrict network access to the Webmin interface to trusted management hosts only.
- Disable or remove the affected package-updates/apt module if it is not needed.
- Audit Webmin accounts and rotate credentials for any host that ran a vulnerable version while exposed.
Detection
- Review Webmin access logs for requests to the apt/package-updates module from unexpected source IPs.
- Monitor for command execution or child processes spawned by the Webmin service (for example shell or apt commands) outside normal update windows.
- Check for unexpected files, cron entries, or new accounts on Webmin hosts as post-exploitation indicators.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2022-36446 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-36446), CISA KEV, FIRST EPSS (scores of 2026-09-25). This page is refreshed as NVD updates the record.