Improper Access Control in Admidio User Management Solution
CVE-2026-47227

6.5MEDIUM

Key Information:

Vendor

Admidio

Status
Vendor
CVE Published:
12 August 2026

What is CVE-2026-47227?

The Admidio user management solution contains a vulnerability that allows users with limited module-administrator rights to manipulate categories across different modules. The issue arises because the code does not properly validate user permissions when performing delete, sequence, or save actions on categories using their UUIDs. This oversight enables unauthorized users to delete or reorder categories they shouldn't have permissions to alter, undermining the integrity of the user management system. Version 5.0.10 addresses this flaw, ensuring proper access control checks are enforced before allowing such actions.

Affected Version(s)

admidio < 5.0.10

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.