Admidio · Admidio · CVE-2026-69090
**Name of the Vulnerable Software and Affected Versions**
Admidio versions prior to 5.0.11
**Description**
Authenticated role administrators can modify roles belonging to other organizations because the software fails to validate target organization membership in role handlers. An attacker can provide a role UUID from a different organization to the `groups roles.php` endpoint to delete, activate, deactivate, or edit those roles without authorization.
**Recommendations**
Update to version 5.0.11 or later.