This release adds 1 notable feature for engineering teams evaluating rollout.
✓ No known CVEs patched in this version
Affected surfaces
Summary
AI summaryAdd global per-user ACL control to block URL downloads from non-public IPs and fix several bugs across modules.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Feature | Medium |
Add global per-user ACL control to block URL downloads from non-public IPs in File Manager, Mailboxes, and Upload/Download modules Add global per-user ACL control to block URL downloads from non-public IPs in File Manager, Mailboxes, and Upload/Download modules Source: llm_adapter@2026-07-18 Confidence: high |
— |
| Bugfix | Medium |
Fix hex numeric HTML entities recognition in various elements Fix hex numeric HTML entities recognition in various elements Source: llm_adapter@2026-07-18 Confidence: high |
— |
| Bugfix | Medium |
Fix `patch` sub-command to reload Webmin instead of restarting, enabling terminal execution Fix `patch` sub-command to reload Webmin instead of restarting, enabling terminal execution Source: llm_adapter@2026-07-18 Confidence: high |
— |
| Bugfix | Medium |
Fix SSL certificate and TCP monitors to report transient failures as down and timeouts as timed out Fix SSL certificate and TCP monitors to report transient failures as down and timeouts as timed out Source: llm_adapter@2026-07-18 Confidence: high |
— |
| Bugfix | Medium |
Enforce file access ACLs for local file imports in Users/Groups, LDAP Users, MySQL/MariaDB, and PostgreSQL modules Enforce file access ACLs for local file imports in Users/Groups, LDAP Users, MySQL/MariaDB, and PostgreSQL modules Source: llm_adapter@2026-07-18 Confidence: high |
— |
| Bugfix | Medium |
Fix Webmin user switching and session checks to locate sessions stored with HMAC keys Fix Webmin user switching and session checks to locate sessions stored with HMAC keys Source: llm_adapter@2026-07-18 Confidence: high |
— |
| Bugfix | Medium |
Fix Usermin user switching to use one-time login URLs instead of legacy cookie handoff and service restart flow Fix Usermin user switching to use one-time login URLs instead of legacy cookie handoff and service restart flow Source: llm_adapter@2026-07-18 Confidence: high |
— |
| Bugfix | Medium |
Fix APT package architecture suffix handling to avoid false update failure reports Fix APT package architecture suffix handling to avoid false update failure reports Source: llm_adapter@2026-07-18 Confidence: high |
— |
| Bugfix | Medium |
Treat missing Maildir folders as empty in Mailboxes module Treat missing Maildir folders as empty in Mailboxes module Source: llm_adapter@2026-07-18 Confidence: high |
— |
| Bugfix | Medium |
Fix Postfix version comparisons to safely handle version strings Fix Postfix version comparisons to safely handle version strings Source: llm_adapter@2026-07-18 Confidence: high |
— |
| Bugfix | Low |
Correct SELinux labeling for Webmin runtime data Correct SELinux labeling for Webmin runtime data Source: granite4.1:30b@2026-07-18-audit Confidence: low |
— |
| Bugfix | Low |
Fix inconsistent gaps around rounded UI elements in Authentic theme Fix inconsistent gaps around rounded UI elements in Authentic theme Source: granite4.1:30b@2026-07-18-audit Confidence: low |
— |
| Bugfix | Low |
Prevent CPU usage values from exceeding 100% in dashboard Prevent CPU usage values from exceeding 100% in dashboard Source: granite4.1:30b@2026-07-18-audit Confidence: low |
— |
| Bugfix | Low |
Ensure File Manager remote downloads respect download address restrictions Ensure File Manager remote downloads respect download address restrictions Source: granite4.1:30b@2026-07-18-audit Confidence: low |
— |
| Bugfix | Low |
Fix spacing in login page welcome message of Authentic theme Fix spacing in login page welcome message of Authentic theme Source: granite4.1:30b@2026-07-18-audit Confidence: low |
— |
| Refactor | Low |
Update Authentic theme to latest version with multiple UI and functionality fixes Update Authentic theme to latest version with multiple UI and functionality fixes Source: granite4.1:30b@2026-07-18-audit Confidence: low |
— |
Full changelog
- Add a global per-user ACL control to block URL downloads from non-public IP addresses in File Manager, Mailboxes, and Upload and Download modules
- Fix to recognize hex numeric HTML entities to work in various elements
- Fix
patchsub-command to reload Webmin instead of restarting, making it possible to run from Terminal module - Fix SSL certificate and TCP monitors to report transient connection failures as down, and SSL check timeouts as timed out, rather than uninstalled
- Fix local file imports to enforce file access ACLs in Users and Groups, LDAP Users, MySQL/MariaDB, and PostgreSQL modules
- Fix Webmin user switching and session checks to find sessions stored with HMAC session keys
- Fix Usermin user switching to use one-time login URLs instead of the legacy cookie handoff and service restart flow
- Fix APT package architecture suffix handling to avoid false package update failure reports
- Fix missing Maildir folders to be counted as empty in Mailboxes module
- Fix Postfix version comparisons to handle version strings safely
- Fix SELinux labeling for Webmin runtime data
- Update the Authentic theme to the latest version with various improvements:
- Fix inconsistent gaps around rounded UI elements
- Fix CPU usage values exceeding 100% in the dashboard
- Fix File Manager remote downloads to respect download address restrictions
- Fix spacing in the login page welcome message
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
Related context
Related tools
Beta — feedback welcome: [email protected]