CVE-2020-35606: Webmin
High severity, CVSS 8.8. EPSS: 28% chance of exploitation in the next 30 days.
Arbitrary command execution can occur in Webmin through 1.962. Any user authorized for the Package Updates module can execute arbitrary commands with root privileges via vectors involving %0A and %0C. NOTE: this issue exists because of an incomplete fix for CVE-2019-12840.
Affected products
- Webmin Webmin: up to and including 1.962
Published 2020-12-21. Last modified 2026-06-17.