Medium severity4.4GHSA Advisory· Published Aug 12, 2026· Updated Aug 12, 2026
CVE-2026-47234
CVE-2026-47234
Description
Admidio is an open-source user management solution. Prior to version 5.0.10, when debug logging is enabled, Session::setCookie() logs full cookie values and Session::start() logs the current session ID. In a real Admidio deployment this includes both the active session cookie and the persistent auto-login cookie. Anyone with access to the log sink can recover live bearer-style credentials from the logs. Version 5.0.10 contains a fix.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
admidio/admidioPackagist | < 5.0.10 | 5.0.10 |
Affected products
1Patches
Vulnerability mechanics
References
4News mentions
1- Admidio: Nine CVEs Disclosed Together — IDOR, CSRF, and Auth Bypass FlawsVypr Intelligence · May 29, 2026