CVE-2026-69094: Admidio before 5.0.11 IDOR via save_temporary mylist_function.php
Admidio before 5.0.11 contains an insecure direct object reference vulnerability in the savetemporary mode of mylistfunction.php that allows authenticated users to hijack list configurations. Attackers can enumerate global list UUIDs and overwrite admin-curated global lists or other users' private lists by supplying a listuuid parameter, transferring ownership and demoting global lists to personal configurations.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Admidioto a version that resolves this vulnerability.Fixed in 5.0.11 - Compensating control
Restrict access to Admidio mylist_function.php save_temporary mode (and/or block untrusted access to the list_uuid parameter) so only authorized users can submit/modify list configurations.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-69094?
The severity of CVE-2026-69094 is medium, rated at 4.3 on the CVSS scale.
How do I fix CVE-2026-69094?
To fix CVE-2026-69094, update Admidio to version 5.0.11 or later.
What kind of vulnerability is CVE-2026-69094?
CVE-2026-69094 is an insecure direct object reference (IDOR) vulnerability.
What can attackers do with CVE-2026-69094?
Attackers can hijack list configurations by enumerating global list UUIDs and overwriting configurations.
Which software is affected by CVE-2026-69094?
The vulnerability affects versions of Admidio before 5.0.11.