Data Exposure Vulnerability in Admidio Open-Source User Management Solution
CVE-2026-41659

2.7LOW

Key Information:

Vendor

Admidio

Status
Vendor
CVE Published:
7 May 2026

What is CVE-2026-41659?

Admidio is a widely used open-source user management system that, prior to version 5.0.9, suffered from a data exposure vulnerability. Specifically, the member assignment DataTables endpoint allowed unauthorized role leaders to access hidden personally identifiable information (PII) such as birthdays, street addresses, and other critical details. This vulnerability arises because SQL queries did not adequately filter for field visibility before processing search requests, thereby unintentionally revealing hidden data through the presence of user records in search results. The issue was subsequently addressed in version 5.0.9, which enhances security by ensuring that only permitted visible fields are included in SQL operations.

Affected Version(s)

admidio < 5.0.9

References

CVSS V3.1

Score:
2.7
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.