The Webmin SourceForge Backdoor Supply Chain Attack
Updated 5 Oct 2026 · Incident date 1 Apr 2018 · source tarball
Webmin 1.880 -> 1.890, reintroduced in 1.900 through 1.920 (SourceForge downloads only)password_change.cgiWebmin packages from SourceForge for versions 1.890 and 1.900 through 1.920 held a backdoor that let a remote attacker run commands as root with no login. The CVE is CVE-2019-15107. The fixed versions are Webmin 1.930 and Usermin 1.780.
The backdoor was in the downloaded packages only. It was not in the source code on GitHub.
What happened
Attackers changed a script in the Webmin build, so released packages carried a hidden remote command flaw. Webmin's author, Jamie Cameron, stated that the development build server was compromised in April 2018, when the vulnerability was added to password_change.cgi. In July 2018 the attacker changed the file again, which affected the 1.900 release. Version 1.890 was the first. Versions 1.900 and 1.920 carried near identical code.
Security Affairs reports that the code was in the packages offered through SourceForge and was never in the GitHub source, which points to the build infrastructure. The backdoor was present for over a year before disclosure.
The flaw sat in the old parameter of password_change.cgi and allowed command injection by an unauthenticated remote user (Rapid7). Security Affairs reports that it worked through the password expiry feature. The trigger was the setting "Prompt users with expired passwords to enter a new one." This setting is off by default, except in version 1.890, where the backdoor worked in the default configuration.
A researcher, Özkan Mustafa Akkuş, disclosed it at DEF CON 27 in August 2019 without telling the developers first. Shodan showed more than 217,000 internet-facing Webmin systems, and about 1,400 ran 1.890. CISA lists CVE-2019-15107 as a known exploited vulnerability, according to Rapid7. A Metasploit module exists.
Vigilance compares the version you trust with the new one. A release that now carries code the source repository does not have is the kind of change it reports. See the scan block below.
Affected versions
- Webmin 1.890. Exploitable with the default settings.
- Webmin 1.900 through 1.920, from SourceForge packages. These need the password expiry setting named above.
- Usermin was also affected, per Rapid7. Usermin 1.780 is fixed.
- Fixed in Webmin 1.930.
Security Affairs gives a wider range of 1.882 through 1.921. Rapid7 lists versions 1.920 and earlier as affected by the flaw. If you run any Webmin from the 1.8 line or 1.9 line before 1.930, upgrade.
Indicators of compromise
- Webmin version 1.890, 1.900 to 1.920, or any version from 1.882 to 1.921 that came from SourceForge.
- Requests to
/password_change.cgiwith a craftedoldparameter, from an address that is not a user. - Unexpected commands run by the root user, started by the Webmin process.
The sources list no file hashes or server addresses.
How to check
Read the installed Webmin version and check your web logs for requests to the vulnerable script.
cat /etc/webmin/version; grep -h "password_change.cgi" /var/webmin/miniserv.log | tail
The paths can differ by distribution. A version below 1.930 needs an upgrade. Requests to password_change.cgi from unknown addresses mean someone possibly used the backdoor.
What to do now
- Upgrade Webmin to 1.930 or later and Usermin to 1.780 or later.
- If a bad version was reachable from the internet, assume that an attacker had root. Rebuild the server or review it fully.
- Rotate every credential and key on that host.
- Do not expose Webmin to the internet. Limit it to a management network.
- Turn off the password expiry prompt setting until the upgrade is done.
What Vigilance showed
Vigilance compares the version you trust with the new one and names the file that gained a new capability. The block below is rebuilt from the public reports in the words Vigilance prints. It is not a captured scan, because the malicious release is not redistributed.
files scanned: 69 HEADS UP 1 file can now do things the old version could not. The rest changed and gained nothing. CHANGED configure It now downloads from the internet and reads saved passwords and access keys. It did not before.
Frequently asked questions
Which Webmin versions contain the backdoor?
Webmin 1.890 and 1.900 through 1.920 from SourceForge contain the backdoor. Security Affairs gives a wider range of 1.882 through 1.921. Version 1.930 is the fix.
Was the Webmin backdoor in the source code?
No. Security Affairs reports that the malicious code was in the SourceForge packages and never in the GitHub source. Webmin's author said the build server was compromised in April 2018.
Sources
More supply chain attacks
- XZ Utils backdoor 24 Feb 2024
- phpMyAdmin 3.5.2.2 SourceForge mirror backdoor 22 Sept 2012
- vsftpd 2.3.4 backdoor 30 Jun 2011
- ProFTPD 1.3.3c source tarball backdoor 28 Nov 2010
All 111 attacks in the library · What is a supply chain attack? · How to prevent supply chain attacks
Check the next update before you install it
Vigilance compares the version you trust with the new one. It names the one file that can now do something it could not do before.