Data Exposure Vulnerability in Admidio Open-Source User Management Solution
CVE-2026-41659
What is CVE-2026-41659?
Admidio is a widely used open-source user management system that, prior to version 5.0.9, suffered from a data exposure vulnerability. Specifically, the member assignment DataTables endpoint allowed unauthorized role leaders to access hidden personally identifiable information (PII) such as birthdays, street addresses, and other critical details. This vulnerability arises because SQL queries did not adequately filter for field visibility before processing search requests, thereby unintentionally revealing hidden data through the presence of user records in search results. The issue was subsequently addressed in version 5.0.9, which enhances security by ensuring that only permitted visible fields are included in SQL operations.
Affected Version(s)
admidio < 5.0.9
