PT-2026-83584 · Admidio · Admidio

·

CVE-2026-82658

·

Published

2026-08-30

·

Updated

2026-09-02

CVSS v4.0

5.3

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Admidio versions prior to 5.0.12
Description Broken access control in profile function.php allows authenticated users with low privileges to view the future role memberships of other users. This is achieved by bypassing profile-level authorization through direct calls to the reload future memberships endpoint using a victim's user UUID.
Recommendations Update to version 5.0.12 or later.

Exploit

Fix

Improper Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-82658
GHSA-4P3X-3RXJ-V7C4

Affected Products

Admidio