CVE-2026-41656General

LOWCVSS 4.5 · MEDIUM

Signal is active with 4 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Admidio is an open-source user management solution. Prior to version 5.0.9, the add mode in modules/documents-files.php accepts a name parameter validated only as 'string' type (HTML encoding), allowing path traversal characters (../) to pass through unfiltered. Combined with the absence of CSRF protection on this endpoint and SameSite=Lax session cookies, a low-privileged attacker can trick a documents administrator into clicking a crafted link that registers an arbitrary server file (e.g., install/config.php containing database credentials) into a documents folder accessible to the attacker. This issue has been patched in version 5.0.9.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • General: 2 classified signals
  • Disclosure: 1 classified signal
  • 4 total mentions across 1 day

Deep dive

Activity timeline4 mentions / 1d
01234Mentions · 2026-05-07: 4Patch / Workaround · 2026-05-07: 1Technical Details · 2026-05-07: 305-07
Signal classification3 categories
General
250.0%
Disclosure
125.0%
Patch
125.0%
Referenced assets4 URLs
Full discourse4 posts
  • Infoflowcloud@infoflowcloud
    General

    🚨*CVE* CVE-2026-41656 Admidio is an open-source user management solution. Prior to version 5.0.9, the add mode in modules/documents-files.php accepts a name parameter validated only as 'st… https://www.cve.org/CVERecord?id=CVE-2026-41656 ----- Traducción: CVE-2026-41656 Adm… http://infoflow.cloud`

    Post summary

    The post merely notes a CVE affecting Admidio prior to version 5.0.9, providing a brief technical detail but lacking PoC, exploit, patch, or exploitation reports.

    0000031
    75 followersView on X
  • CVE@CVEnew
    Patch

    CVE-2026-41656 Admidio is an open-source user management solution. Prior to version 5.0.9, the add mode in modules/documents-files.php accepts a name parameter validated only as 'st… https://www.cve.org/CVERecord?id=CVE-2026-41656

    Post summary

    The text warns of a validation weakness in Admidio's documents-files.php module that is addressed by upgrading to version 5.0.9, highlighting the availability of a patch.

    00000108
    57.4K followersView on X
  • CVEarity@CVEarity
    General

    ⚡ New CVE Alert: CVE-2026-41656 📊 Severity: 4.5 🚨 Risk Level: Medium 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-41656 #CVE-2026-41656 #CVE #Medium #CyberSecurity #InfoSec https://t.co/8RhuyCgaFl

    Post summary

    The tweet announces CVE-2026-41656 with a moderate severity rating but provides no further technical or operational details.

    0000042
    152 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-41656 Path Traversal in Admidio Prior to Version 5.0.9 Documents Module https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-41656

    Post summary

    The post announces a path traversal vulnerability in Admidio documents module affecting versions prior to 5.0.9, with no additional details on exploits, patches, or active usage.

    0000041
    4.0K followersView on X

Explore more