Open-source User Management Solution Vulnerability in Admidio
CVE-2026-41663

3.5LOW

Key Information:

Vendor

Admidio

Status
Vendor
CVE Published:
7 May 2026

What is CVE-2026-41663?

Admidio, an open-source user management solution, has a vulnerability in its preferences module where several administrative operations, such as database backup, test email, and htaccess generation, can be triggered via GET requests without proper CSRF token validation. This flaw allows attackers to exploit the feature by forcing an authenticated administrator to perform these operations from a malicious webpage. The vulnerability has been addressed in version 5.0.9, where necessary security measures have been implemented to prevent such unauthorized actions.

Affected Version(s)

admidio < 5.0.9

References

CVSS V3.1

Score:
3.5
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.