VYPR
Unrated severityOSV Advisory· Published Aug 3, 2026· Updated Aug 3, 2026

Admidio before 5.0.11 Authentication Bypass via forum.php

CVE-2026-69091

Description

Admidio before 5.0.11 contains an authentication bypass vulnerability in the forum module when configured in login-only mode. The access control logic in modules/forum.php fails to validate the login-only configuration state, allowing unauthenticated attackers to read forum topics and posts by directly accessing the module with read-only parameters.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

2
  • Admidio/AdmidioOSV2 versions
    v5.0-Beta.1, v4.3-Beta.1, v4.1-Beta.2, …+ 1 more
    • (no CPE)range: v5.0-Beta.1, v4.3-Beta.1, v4.1-Beta.2, …
    • (no CPE)range: <5.0.11

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.

CVE-2026-69091 · VYPR