MEDIUM 6.9 NVD
CVE-2026-69090
Admidio before 5.0.11 fails to validate target organization membership in role handlers, allowing authenticated role administrators to delete, activate, deactiv
Admidio before 5.0.11 fails to validate target organization membership in role handlers, allowing authenticated role administrators to delete, activate, deactivate, or edit roles belonging to other organizations. Attackers can supply a role UUID from another organization to groups_roles.php handlers to modify that organization's roles without authorization.
References
- https://github.com/Admidio/admidio/security/advisories/GHSA-fcq9-w4hp-xchg
- https://www.vulncheck.com/advisories/admidio-before-cross-organization-role-modification
- https://github.com/Admidio/admidio/security/advisories/GHSA-fcq9-w4hp-xchg
This medium severity vulnerability with a CVSS score of 6.9 was published on 2026-08-03 via NVD.
vulnfeed aggregates 9166 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.