CVE-2026-34382Disclosure(admidio / admidio)

LOWCVSS 4.6 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Admidio is an open-source user management solution. From version 5.0.0 to before version 5.0.8, the delete mode handler in mylist_function.php permanently deletes list configurations without validating a CSRF token. An attacker who can lure an authenticated user to a malicious page can silently destroy that user's list configurations — including organization-wide shared lists when the victim holds administrator rights. This issue has been patched in version 5.0.8.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-352

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • admidio

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • Disclution: 1 classified signal
  • 2 total mentions across 1 day

Affected systems

Vendors
Products
admidio

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-04-01: 2Technical Details · 2026-04-01: 104-01
Signal classification2 categories
Disclosure
150.0%
Disclution
150.0%
Referenced assets2 URLs
Full discourse2 posts
  • Juan Felipe Oz@PwnedRar_
    Disclution

    I've been doing research, and i got some new CVEs: CVE-2026-34406 (Critical 9.4) - APTRS CVE-2026-34381 (High 7.5) CVE-2026-34382 (Medium 4.6) https://github.com/APTRS/APTRS/security/advisories/GHSA-gv25-wp4h-9c35 #researching #0days #cibersecurity #hacking #cve

    Post summary

    The user lists three newly discovered CVEs with associated severity scores and provides a GitHub advisory link, but offers no additional technical details, exploit code, or mitigation instruction.

    0001061
    116 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-34382 Admidio is an open-source user management solution. From version 5.0.0 to before version 5.0.8, the delete mode handler in mylist_function.php permanently deletes lis… https://www.cve.org/CVERecord?id=CVE-2026-34382

    Post summary

    The entry announces CVE‑2026‑34382 for Admidio, noting that the delete mode handler can permanently erase list items, but provides no proof of exploitation, PoC, or mitigation.

    00010129
    56.9K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appadmidioadmidio---

Explore more