CVE-2026-30927Disclosure(admidio / admidio)

LOWCVSS 5.4 · MEDIUM

Signal is active with 4 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Admidio is an open-source user management solution. Prior to 5.0.6, in modules/events/events_function.php, the event participation logic allows any user who can participate in an event to register OTHER users by manipulating the user_uuid GET parameter. The condition uses || (OR), meaning if possibleToParticipate() returns true (event is open for participation), ANY user - not just leaders - can specify a different user_uuid and register/cancel participation for that user. The code then operates on $user->getValue('usr_id') (the target user from user_uuid) rather than the current user. This vulnerability is fixed in 5.0.6.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-639

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • admidio

Threat summary

  • 4 mentions across 1 observed day

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • 4 total mentions across 1 day

Affected systems

Vendors
Products
admidio

Deep dive

Activity timeline4 mentions / 1d
01234Mentions · 2026-03-10: 4Technical Details · 2026-03-10: 303-10
Signal classification2 categories
Disclosure
375.0%
General
125.0%
Referenced assets4 URLs
Full discourse4 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-30927 Unauthenticated User Registration Vulnerability in Admidio Event Management Module https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-30927

    Post summary

    A new unauthenticated user registration vulnerability (CVE‑2026‑30927) affecting the Admidio Event Management Module has been disclosed, with details posted on Vulmon.

    0000040
    4.0K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-30927 Admidio is an open-source user management solution. Prior to 5.0.6, in modules/events/events_function.php, the event participation logic allows any user who can parti… https://www.cve.org/CVERecord?id=CVE-2026-30927 ----- Traducción: CVE-2026-30927 Adm… http://infoflow.cloud`

    Post summary

    The post references CVE-2026-30927, identifying a flaw in Admidio's event participation logic before version 5.0.6, but offers no PoC, exploit, patch, or evidence of active use.

    0000033
    57 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-30927 Admidio is an open-source user management solution. Prior to 5.0.6, in modules/events/events_function.php, the event participation logic allows any user who can parti… https://www.cve.org/CVERecord?id=CVE-2026-30927

    Post summary

    The excerpt briefly notes CVE-2026-30927 in Admidio, mentioning a flaw in event participation logic prior to v5.0.6, but offers no PoC, exploit, patch, or detailed technical information.

    00000200
    56.7K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-30927 - Admidio: Event participation IDOR - non-leaders can register other users for events via user_uuid parameter Intel Report: https://ift.tt/jV3vhu7

    Post summary

    The tweet announces CVE-2026-30927, detailing an IDOR flaw in Admidio that lets non‑leaders register any user for events via the user_uuid parameter.

    0000035
    347 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appadmidioadmidio---

Explore more