PT-2026-83581 · Admidio · Admidio

·

CVE-2026-82655

·

Published

2026-08-30

·

Updated

2026-09-04

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Admidio versions prior to 5.0.12
Description An issue exists that allows unauthenticated attackers to execute arbitrary SQL queries. By providing a dummy UUID in the role list parameter, attackers can bypass authentication and use the relation type list parameter in the 'lists show.php' endpoint to extract sensitive database contents, such as user credentials and password hashes. This is achieved through blind SQL injection, a technique used to retrieve data from a database by asking a series of true or false questions based on the application's response.
Recommendations Update to version 5.0.12 or later. Avoid using the relation type list parameter in the 'lists show.php' endpoint until the update is applied.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-82655
GHSA-P5CP-MHVX-W392

Affected Products

Admidio