Authorization Bypass in Admidio Inventory Module by Admidio
CVE-2026-41658

6.5MEDIUM

Key Information:

Vendor

Admidio

Status
Vendor
CVE Published:
7 May 2026

What is CVE-2026-41658?

The Admidio inventory module, prior to version 5.0.9, contains an authorization bypass vulnerability. This flaw allows any authenticated user with access to the inventory module to perform destructive operations such as deleting, retiring, or reinstating inventory items without proper authorization checks. While the UI may restrict access by rendering buttons conditionally, the backend processes fail to confirm if the user has the necessary permissions. As a result, any authenticated user can exploit this vulnerability to permanently delete inventory items and all associated data, posing a serious risk to the integrity of the inventory management system.

Affected Version(s)

admidio < 5.0.9

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.