CVE-2026-32813Disclosure(admidio / admidio)

LOWCVSS 8.0 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Admidio is an open-source user management solution. Versions 5.0.6 and below are vulnerable to arbitrary SQL Injection through the MyList configuration feature. The MyList configuration feature lets authenticated users define custom list column layouts, storing user-supplied column names, sort directions, and filter conditions in the adm_list_columns table via prepared statements. However, these stored values are later read back and interpolated directly into dynamically constructed SQL queries without sanitization or parameterization, creating a classic second-order SQL injection vulnerability (safe write, unsafe read). An attacker can exploit this to inject arbitrary SQL, potentially reading, modifying, or deleting any data in the database and achieving full database compromise. This issue has been fixed in version 5.0.7.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-89

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • admidio

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • Peaked 1d ago at 2 mentions (2026-03-20); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
admidio

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-03-20: 2Mentions · 2026-03-21: 1Technical Details · 2026-03-20: 2Technical Details · 2026-03-21: 103-2003-21
Signal classification1 categories
Disclosure
3100.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-03-202
Disclosure2
2026-03-211
Disclosure1
Full discourse3 posts
  • PulsePatch.io@pulsepatchio
    Disclosure

    `Admidio` has a High-severity Second-Order SQL Injection (CVE-2026-32813) via List Configuration. Potential for unauthorized database access. Monitor for updates. #Admidio #SQLi #infosec https://www.pulsepatch.io/posts/cve-2026-32813-admidio-sql-injection

    Post summary

    Admidio is vulnerable to a high‑severity second‑order SQL injection through list configuration, which could enable unauthorized database access; administrators are advised to watch for patches.

    0000028
    2 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-32813 - High Admidio is an open-source user management solution. Versions 5.0.6 and below are vulnerable to arbitrary SQL Injection through the MyList configuration feature. The MyList configuration featu... https://www.thehackerwire.com/vulnerability/CVE-2026-32813/ https://t.co/KJlVeT3w6l

    Post summary

    Admidio versions 5.0.6 and earlier are vulnerable to arbitrary SQL injection via the MyList configuration feature, as identified by CVE-2026‑32813.

    0000043
    138 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-32813 Admidio is an open-source user management solution. Versions 5.0.6 and below are vulnerable to arbitrary SQL Injection through the MyList configuration feature. The M… https://www.cve.org/CVERecord?id=CVE-2026-32813

    Post summary

    The text announces a CVE‑2026‑32813 SQL injection vulnerability in Admidio v5.0.6 and earlier, detailing the vulnerable feature but providing no PoC, exploit code, patch, or active exploitation evidence.

    0000077
    56.8K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appadmidioadmidio---

Explore more