Logic Error in Two-Factor Authentication Reset in Admidio User Management Solution
CVE-2026-41660
7.1HIGH
What is CVE-2026-41660?
Admidio, an open-source user management solution, contains a logic error in its two-factor authentication reset mechanism before version 5.0.9. This vulnerability allows non-admin users to remove TOTP configurations of other users, including administrators, despite not being able to remove their own TOTP. A group leader with profile edit rights can exploit this flaw to strip the two-factor authentication from admin accounts. This issue has been addressed and patched in version 5.0.9.
Affected Version(s)
admidio < 5.0.9
