PT-2026-83582 · Admidio · Admidio

·

CVE-2026-82656

·

Published

2026-08-30

·

Updated

2026-08-30

CVSS v3.1

2.6

Low

VectorAV:N/AC:H/PR:L/UI:R/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Admidio versions prior to 5.0.12
Description Insufficient sanitization of album names in the photo ZIP download functionality allows authenticated users with album-creation rights to include path traversal segments in archive entry names. This enables attackers to create malicious album names containing directory traversal sequences—a technique used to access files and directories outside the intended folder—which can result in files being written outside the target directory when the recipient extracts the archive.
Recommendations Update to version 5.0.12 or later.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-82656
GHSA-GM42-RF3M-682V

Affected Products

Admidio