Unrated severityOSV Advisory· Published Aug 3, 2026· Updated Aug 3, 2026
Admidio before 5.0.11 Cross-Organization Role Modification
CVE-2026-69090
Description
Admidio before 5.0.11 fails to validate target organization membership in role handlers, allowing authenticated role administrators to delete, activate, deactivate, or edit roles belonging to other organizations. Attackers can supply a role UUID from another organization to groups_roles.php handlers to modify that organization's roles without authorization.
Affected products
2Patches
Vulnerability mechanics
References
2- github.com/Admidio/admidio/security/advisories/GHSA-fcq9-w4hp-xchgmitrevendor-advisory
- www.vulncheck.com/advisories/admidio-before-cross-organization-role-modificationmitrethird-party-advisory
News mentions
0No linked articles in our index yet.