CVE-2026-41659General

LOWCVSS 2.7 · LOW

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Admidio is an open-source user management solution. Prior to version 5.0.9, the member assignment DataTables endpoint (members_assignment_data.php) includes hidden profile fields (BIRTHDAY, STREET, CITY, POSTCODE, COUNTRY) in its SQL search condition regardless of field visibility settings. While the JSON output correctly suppresses hidden columns via isVisible() checks, the server-side search operates at the SQL level before any visibility filtering. This allows a role leader with assign-only permissions to infer hidden PII values by observing which users appear in search results for specific values. This issue has been patched in version 5.0.9.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-200

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • General: 2 classified signals
  • Disclosure: 1 classified signal
  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-05-07: 3Technical Details · 2026-05-07: 205-07
Signal classification2 categories
General
266.7%
Disclosure
133.3%
Referenced assets3 URLs
Full discourse3 posts
  • CVE@CVEnew
    General

    CVE-2026-41659 Admidio is an open-source user management solution. Prior to version 5.0.9, the member assignment DataTables endpoint (members_assignment_data.php) includes hidden pr… https://www.cve.org/CVERecord?id=CVE-2026-41659

    Post summary

    The text briefly describes CVE-2026-41659 affecting Admidio before v5.0.9, noting a problem with the members_assignment_data.php endpoint, but provides no PoC, exploitation evidence, patch or mitigation details.

    00000100
    57.4K followersView on X
  • CVEarity@CVEarity
    General

    ⚡ New CVE Alert: CVE-2026-41659 📊 Severity: 2.7 🚨 Risk Level: Low 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-41659 #CVE-2026-41659 #CVE #Low #CyberSecurity #InfoSec https://t.co/dIKcElgYg1

    Post summary

    The tweet merely announces CVE‑2026‑41659 with a severity rating and a link to NVD, providing no further technical, exploit, or mitigation details.

    0000048
    152 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-41659 Information Disclosure of Hidden Profile Fields in Admidio Prior to Version 5.0.9 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-41659

    Post summary

    CVE-2026-41659 is an information‑disclosure vulnerability affecting Admidio before 5.0.9; no PoC, exploit, or patch details are given.

    0000038
    4.0K followersView on X

Explore more