Vulnerability in Admidio Open-Source User Management Solution
CVE-2026-47229

5.4MEDIUM

Key Information:

Vendor

Admidio

Status
Vendor
CVE Published:
12 August 2026

What is CVE-2026-47229?

Admidio, an open-source user management solution, has a significant vulnerability in its handling of state-changing actions within its SSO module. Specifically, the adm_csrf_token is not validated during the enabling of SAML or OIDC clients. This leaves the action vulnerable to exploitation through GET requests, allowing unauthorized changes to the status of SSO clients. If an authenticated administrator is tricked into performing this action, it can lead to disruptions for any connected applications that rely on the affected SSO clients. As a precaution, users should upgrade to version 5.0.10, which addresses this security oversight.

Affected Version(s)

admidio < 5.0.10

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.