User Management Solution Vulnerability in Admidio Affects Multiple Versions
CVE-2026-34383

4.3MEDIUM

Key Information:

Vendor

Admidio

Status
Vendor
CVE Published:
31 March 2026

What is CVE-2026-34383?

The Admidio user management solution prior to version 5.0.8 contains a vulnerability in the inventory module. An unauthenticated user can exploit the item_save endpoint by sending a POST request with a user-controlled parameter, effectively circumventing CSRF token checks and server-side validations. This allows attackers to submit arbitrary inventory data, compromising the integrity of the user management system. The vulnerability was addressed in the release of version 5.0.8, prompting all users to upgrade to ensure security.

Affected Version(s)

admidio < 5.0.8

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.