Vulnerability in Admidio Open-Source User Management Solution
CVE-2026-47229
5.4MEDIUM
What is CVE-2026-47229?
Admidio, an open-source user management solution, has a significant vulnerability in its handling of state-changing actions within its SSO module. Specifically, the adm_csrf_token is not validated during the enabling of SAML or OIDC clients. This leaves the action vulnerable to exploitation through GET requests, allowing unauthorized changes to the status of SSO clients. If an authenticated administrator is tricked into performing this action, it can lead to disruptions for any connected applications that rely on the affected SSO clients. As a precaution, users should upgrade to version 5.0.10, which addresses this security oversight.
Affected Version(s)
admidio < 5.0.10
