Broken Access Control in Admidio Allows Unauthorized Access to Membership Information
CVE-2026-82658

5.3MEDIUM

Key Information:

Vendor

Admidio

Status
Vendor
CVE Published:
30 August 2026

What is CVE-2026-82658?

In Admidio versions before 5.0.12, a broken access control vulnerability exists in the profile_function.php file. This flaw allows authenticated low-privilege users to access sensitive information regarding other users' future role memberships. Attackers can exploit this vulnerability by directly invoking the reload_future_memberships endpoint with the UUID of a target user's profile, thus circumventing necessary authorization checks and exposing potentially sensitive membership data.

Affected Version(s)

admidio 0 < 5.0.12

admidio 5.0.12

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Leousum
.