VYPR
Medium severity4.4GHSA Advisory· Published Aug 12, 2026· Updated Aug 12, 2026

CVE-2026-47234

CVE-2026-47234

Description

Admidio is an open-source user management solution. Prior to version 5.0.10, when debug logging is enabled, Session::setCookie() logs full cookie values and Session::start() logs the current session ID. In a real Admidio deployment this includes both the active session cookie and the persistent auto-login cookie. Anyone with access to the log sink can recover live bearer-style credentials from the logs. Version 5.0.10 contains a fix.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
admidio/admidioPackagist
< 5.0.105.0.10

Affected products

1

Patches

Vulnerability mechanics

References

4

News mentions

1