CVE-2026-69090: Admidio before 5.0.11 Cross-Organization Role Modification
Admidio before 5.0.11 fails to validate target organization membership in role handlers, allowing authenticated role administrators to delete, activate, deactivate, or edit roles belonging to other organizations. Attackers can supply a role UUID from another organization to groupsroles.php handlers to modify that organization's roles without authorization.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-69090?
The severity of CVE-2026-69090 is medium with a CVSS score of 4.9.
How do I fix CVE-2026-69090?
To fix CVE-2026-69090, upgrade Admidio to version 5.0.11 or later.
What are the potential impacts of CVE-2026-69090?
CVE-2026-69090 allows authenticated role administrators to modify roles from other organizations, potentially leading to unauthorized role changes.
Who is affected by CVE-2026-69090?
CVE-2026-69090 affects all versions of Admidio prior to 5.0.11.
What type of vulnerability is CVE-2026-69090?
CVE-2026-69090 is a cross-organization role modification vulnerability.