CVE-2026-69090 PUBLISHED

Admidio before 5.0.11 Cross-Organization Role Modification

Assigner: VulnCheck
Reserved: 03.08.2026 Published: 03.08.2026 Updated: 03.08.2026

Admidio before 5.0.11 fails to validate target organization membership in role handlers, allowing authenticated role administrators to delete, activate, deactivate, or edit roles belonging to other organizations. Attackers can supply a role UUID from another organization to groups_roles.php handlers to modify that organization's roles without authorization.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
CVSS Score: 6.9

Product Status

Vendor Admidio
Product admidio
Versions Default: unaffected
  • affected from 0 to 5.0.11 (excl.)
  • Version 5.0.11 is unaffected

Credits

  • adamyordan reporter

References

Problem Types

  • Missing Authorization CWE