Description
Admidio versions before 5.0.12 contain a broken access control vulnerability in profile_function.php that allows authenticated low-privilege users to read another user's future role memberships. Attackers can bypass profile-level authorization by directly calling the reload_future_memberships endpoint with a victim's user UUID to disclose sensitive membership information.
Published: 2026-08-30
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Admidio versions prior to 5.0.12 contain a broken access control flaw in profile_function.php. The vulnerability allows authenticated low‑privilege users to read another user’s future role memberships by bypassing profile‑level authorization. Attackers can invoke the reload_future_memberships endpoint with a victim’s user UUID to disclose membership information that should be restricted.

Affected Systems

The affected product is Admidio community edition. All installations of Admidio before version 5.0.12 are impacted. No specific distribution or build is singled out, so any deployment using a vulnerable version is at risk.

Risk and Exploitability

The CVSS score of 5.3 indicates a moderate severity. The EPSS score is not available, so the current likelihood of exploitation is unclear, but the vulnerability requires only that the attacker has legitimate credentials with low privileges. The KEV database does not list this CVE, suggesting that it has not yet been widely exploited, but the exposed information is potentially sensitive. An attacker with access to the application, even at a low privilege level, can collect membership data that may be useful for further social engineering or privilege escalation.

Generated by OpenCVE AI on August 30, 2026 at 15:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Admidio to version 5.0.12 or later to apply the vendor fix.
  • Restrict access to the reload_future_memberships endpoint so that only users with appropriate administrative or membership-management roles can invoke it.
  • Disable or remove the direct endpoint call if it is not required for normal operations.
  • Audit application logs for attempts to call the endpoint with other users’ UUIDs and investigate any anomalies.

Generated by OpenCVE AI on August 30, 2026 at 15:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 30 Aug 2026 14:45:00 +0000

Type Values Removed Values Added
Description Admidio versions before 5.0.12 contain a broken access control vulnerability in profile_function.php that allows authenticated low-privilege users to read another user's future role memberships. Attackers can bypass profile-level authorization by directly calling the reload_future_memberships endpoint with a victim's user UUID to disclose sensitive membership information.
Title Admidio before 5.0.12 Broken Access Control via profile_function.php
First Time appeared Admidio
Admidio admidio
Weaknesses CWE-285
CPEs cpe:2.3:a:admidio:admidio:*:*:*:*:*:*:*:*
Vendors & Products Admidio
Admidio admidio
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-08-30T14:33:38.044Z

Reserved: 2026-08-30T13:38:29.951Z

Link: CVE-2026-82658

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-30T15:16:46.747

Modified: 2026-08-30T15:16:46.747

Link: CVE-2026-82658

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-30T16:30:17Z

Weaknesses