Medium severity4.3GHSA Advisory· Published Aug 12, 2026
CVE-2026-47232
CVE-2026-47232
Description
Admidio is an open-source user management solution. Prior to version 5.0.10, the sensitive mode=export action in modules/sso/keys.php exports a PKCS#12 bundle containing the configured private key and certificate, but the CSRF validation line is commented out. A forged cross-site POST from an administrator session can therefore trigger private key export without a valid form token. Version 5.0.10 contains a fix.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
admidio/admidioPackagist | < 5.0.10 | 5.0.10 |
Affected products
1Patches
Vulnerability mechanics
References
4News mentions
1- Admidio: Nine CVEs Disclosed Together — IDOR, CSRF, and Auth Bypass FlawsVypr Intelligence · May 29, 2026