Skip to content

webmin

v2.652 Feature

This release adds 1 notable feature for engineering teams evaluating rollout.

✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →

✓ No known CVEs patched in this version

Affected surfaces

auth rbac

Summary

AI summary

Add global per-user ACL control to block URL downloads from non-public IPs and fix several bugs across modules.

Changes in this release

Feature Medium

Add global per-user ACL control to block URL downloads from non-public IPs in File Manager, Mailboxes, and Upload/Download modules

Add global per-user ACL control to block URL downloads from non-public IPs in File Manager, Mailboxes, and Upload/Download modules

Source: llm_adapter@2026-07-18

Confidence: high

Bugfix Medium

Fix hex numeric HTML entities recognition in various elements

Fix hex numeric HTML entities recognition in various elements

Source: llm_adapter@2026-07-18

Confidence: high

Bugfix Medium

Fix `patch` sub-command to reload Webmin instead of restarting, enabling terminal execution

Fix `patch` sub-command to reload Webmin instead of restarting, enabling terminal execution

Source: llm_adapter@2026-07-18

Confidence: high

Bugfix Medium

Fix SSL certificate and TCP monitors to report transient failures as down and timeouts as timed out

Fix SSL certificate and TCP monitors to report transient failures as down and timeouts as timed out

Source: llm_adapter@2026-07-18

Confidence: high

Bugfix Medium

Enforce file access ACLs for local file imports in Users/Groups, LDAP Users, MySQL/MariaDB, and PostgreSQL modules

Enforce file access ACLs for local file imports in Users/Groups, LDAP Users, MySQL/MariaDB, and PostgreSQL modules

Source: llm_adapter@2026-07-18

Confidence: high

Bugfix Medium

Fix Webmin user switching and session checks to locate sessions stored with HMAC keys

Fix Webmin user switching and session checks to locate sessions stored with HMAC keys

Source: llm_adapter@2026-07-18

Confidence: high

Bugfix Medium

Fix Usermin user switching to use one-time login URLs instead of legacy cookie handoff and service restart flow

Fix Usermin user switching to use one-time login URLs instead of legacy cookie handoff and service restart flow

Source: llm_adapter@2026-07-18

Confidence: high

Bugfix Medium

Fix APT package architecture suffix handling to avoid false update failure reports

Fix APT package architecture suffix handling to avoid false update failure reports

Source: llm_adapter@2026-07-18

Confidence: high

Bugfix Medium

Treat missing Maildir folders as empty in Mailboxes module

Treat missing Maildir folders as empty in Mailboxes module

Source: llm_adapter@2026-07-18

Confidence: high

Bugfix Medium

Fix Postfix version comparisons to safely handle version strings

Fix Postfix version comparisons to safely handle version strings

Source: llm_adapter@2026-07-18

Confidence: high

Bugfix Low

Correct SELinux labeling for Webmin runtime data

Correct SELinux labeling for Webmin runtime data

Source: granite4.1:30b@2026-07-18-audit

Confidence: low

Bugfix Low

Fix inconsistent gaps around rounded UI elements in Authentic theme

Fix inconsistent gaps around rounded UI elements in Authentic theme

Source: granite4.1:30b@2026-07-18-audit

Confidence: low

Bugfix Low

Prevent CPU usage values from exceeding 100% in dashboard

Prevent CPU usage values from exceeding 100% in dashboard

Source: granite4.1:30b@2026-07-18-audit

Confidence: low

Bugfix Low

Ensure File Manager remote downloads respect download address restrictions

Ensure File Manager remote downloads respect download address restrictions

Source: granite4.1:30b@2026-07-18-audit

Confidence: low

Bugfix Low

Fix spacing in login page welcome message of Authentic theme

Fix spacing in login page welcome message of Authentic theme

Source: granite4.1:30b@2026-07-18-audit

Confidence: low

Refactor Low

Update Authentic theme to latest version with multiple UI and functionality fixes

Update Authentic theme to latest version with multiple UI and functionality fixes

Source: granite4.1:30b@2026-07-18-audit

Confidence: low

Full changelog
  • Add a global per-user ACL control to block URL downloads from non-public IP addresses in File Manager, Mailboxes, and Upload and Download modules
  • Fix to recognize hex numeric HTML entities to work in various elements
  • Fix patch sub-command to reload Webmin instead of restarting, making it possible to run from Terminal module
  • Fix SSL certificate and TCP monitors to report transient connection failures as down, and SSL check timeouts as timed out, rather than uninstalled
  • Fix local file imports to enforce file access ACLs in Users and Groups, LDAP Users, MySQL/MariaDB, and PostgreSQL modules
  • Fix Webmin user switching and session checks to find sessions stored with HMAC session keys
  • Fix Usermin user switching to use one-time login URLs instead of the legacy cookie handoff and service restart flow
  • Fix APT package architecture suffix handling to avoid false package update failure reports
  • Fix missing Maildir folders to be counted as empty in Mailboxes module
  • Fix Postfix version comparisons to handle version strings safely
  • Fix SELinux labeling for Webmin runtime data
  • Update the Authentic theme to the latest version with various improvements:
    • Fix inconsistent gaps around rounded UI elements
    • Fix CPU usage values exceeding 100% in the dashboard
    • Fix File Manager remote downloads to respect download address restrictions
    • Fix spacing in the login page welcome message

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track webmin

Get notified when new releases ship.

Sign up free

About webmin

Powerful and flexible web-based server management control panel

All releases →

Related context

Beta — feedback welcome: [email protected]