CVE-2026-32817Disclosure(admidio / admidio)

LOWCVSS 9.1 · CRITICAL

Signal is active with 4 mentions in latest observed window

Immediate actions

  • Patch admidio admidio systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Admidio is an open-source user management solution. In versions 5.0.0 through 5.0.6, the documents and files module does not verify whether the current user has permission to delete folders or files. The folder_delete and file_delete action handlers in modules/documents-files.php only perform a VIEW authorization check (getFolderForDownload / getFileForDownload) before calling delete(), and they never validate a CSRF token. Because the target UUIDs are read from $_GET, deletion can be triggered by a plain HTTP GET request. When the module is in public mode (documents_files_module_enabled = 1) and a folder is marked public (fol_public = true), an unauthenticated attacker can permanently destroy the entire document library. Even when the module requires login, any user with view-only access can delete content they are only permitted to read. This issue has been fixed in version 5.0.7.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-862

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • admidio

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked at 4 mentions on most recent observed day (2026-03-20)
  • 5 total mentions across 2 days

Affected systems

Vendors
Products
admidio

Deep dive

Activity timeline5 mentions / 2d
01234Mentions · 2026-03-19: 1Mentions · 2026-03-20: 4Patch / Workaround · 2026-03-20: 1Technical Details · 2026-03-19: 1Technical Details · 2026-03-20: 303-1903-20
Signal classification3 categories
Disclosure
360.0%
General
120.0%
Patch
120.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-03-191
Disclosure1
2026-03-204
Disclosure2General1Patch1
Full discourse5 posts
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-32817 - Critical Admidio is an open-source user management solution. In versions 5.0.0 through 5.0.6, the documents and files module does not verify whether the current user has permission to delete folde... https://www.thehackerwire.com/vulnerability/CVE-2026-32817/ https://t.co/Rt6FDK42cz

    Post summary

    This post announces a critical permission‑check vulnerability in Admidio that could allow any user to delete folders, but it does not provide PoC, exploit code, patch, or evidence of active exploitation.

    0000043
    138 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-32817 Admidio is an open-source user management solution. In versions 5.0.0 through 5.0.6, the documents and files module does not verify whether the current user has permi… https://www.cve.org/CVERecord?id=CVE-2026-32817

    Post summary

    The post notes CVE‑2026‑32817 in Admidio 5.0.0‑5.0.6 for missing permission checks in the documents/files module, but offers no further technical details, exploit info, or remediation guidance.

    0000085
    56.8K followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-32817: CRITICAL] Cybersecurity alert: Admidio v5.0.0-5.0.6 has a critical flaw allowing unauthorized deletion of files. Update to v5.0.7 to fix the vulnerability and secure your user management sys...#cve,CVE-2026-32817,#cybersecurity https://cvefind.com/CVE-2026-32817

    Post summary

    Admidio v5.0.0-5.0.6 contains a critical flaw enabling unauthorized file deletion; the vendor recommends upgrading to v5.0.7 for remediation.

    0000045
    604 followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-32817: Admidio is Missing Authorization... GET-based folder nuking with zero auth checks - any script kiddie can wipe entire document libraries via CSRF in public... https://zerodaysignal.com/vulnerability/CVE-2026-32817 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The post announces CVE‑2026‑32817 as an authorization bypass via CSRF that allows folder deletion, providing technical details but no patch, PoC, or evidence of active exploitation.

    0000063
    155 followersView on X
  • PulsePatch.io@pulsepatchio
    Disclosure

    Admidio is vulnerable to unauthorized document/folder deletion (CVE-2026-32817) due to missing auth & CSRF protection. Monitor for vendor updates. #Admidio #infosec #websecurity https://www.pulsepatch.io/posts/cve-2026-32817-admidio-missing-authorization-csrf

    Post summary

    Admidio CVE-2026-32817 permits unauthorized deletion of documents/folders owing to missing auth and CSRF protection; users are urged to monitor vendor updates.

    0000034
    1 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appadmidioadmidio---

Explore more