Improper Access Control in Admidio User Management Solution
CVE-2026-47227
6.5MEDIUM
What is CVE-2026-47227?
The Admidio user management solution contains a vulnerability that allows users with limited module-administrator rights to manipulate categories across different modules. The issue arises because the code does not properly validate user permissions when performing delete, sequence, or save actions on categories using their UUIDs. This oversight enables unauthorized users to delete or reorder categories they shouldn't have permissions to alter, undermining the integrity of the user management system. Version 5.0.10 addresses this flaw, ensuring proper access control checks are enforced before allowing such actions.
Affected Version(s)
admidio < 5.0.10
