MEDIUM 5.3 NVD

CVE-2026-82658

Admidio versions before 5.0.12 contain a broken access control vulnerability in profile_function.php that allows authenticated low-privilege users to read anoth

Admidio versions before 5.0.12 contain a broken access control vulnerability in profile_function.php that allows authenticated low-privilege users to read another user's future role memberships. Attackers can bypass profile-level authorization by directly calling the reload_future_memberships endpoint with a victim's user UUID to disclose sensitive membership information.

References

Published: 2026-08-30 · Source: NVD · Feed updated: 2026-08-30
This medium severity vulnerability with a CVSS score of 5.3 was published on 2026-08-30 via NVD.
vulnfeed aggregates 11475 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.