216.73.217.24

CVE-2026-41658

· Published 07/05/2026 04:16 · Modified 07/05/2026 15:16

Labels: CVE-2026-41658 2026-05-07CVE-2026-41658CWE-862[email protected]

Essential information

Published
07/05/2026 04:16
Modified
07/05/2026 15:16
Author
Creator
CVSS
6.5 MEDIUM (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

CVSS metrics

Description

Admidio is an open-source user management solution. Prior to version 5.0.9, the Admidio inventory module enforces authorization for destructive operations (delete, retire, reinstate) only in the UI layer by conditionally rendering buttons. The backend POST handlers at modules/inventory.php for item_delete, item_retire, item_reinstate, item_picture_upload, item_picture_save, and item_picture_delete perform CSRF validation but never check whether the requesting user is an inventory administrator. Any authenticated user who can access the inventory module can permanently delete any inventory item and all its associated data. This issue has been patched in version 5.0.9.

NVD status

Status
Deferred — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
admidio / admidio cpe:2.3:a:admidio:admidio:*:*:*:*:*:*:*:*
admidio / admidio cpe:2.3:a:admidio:admidio:<5.0.9:*:*:*:*:*:*:*

References