A vulnerability categorized as critical has been discovered in Webmin up to 2.639. Impacted is an unknown function of the component 2FA. The manipulation results in privilege escalation.
This vulnerability is reported as CVE-2026-42210. The attack can be launched remotely. No exploit exists.