CVE-2026-41662Disclosure

LOWCVSS 5.2 · MEDIUM

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Admidio is an open-source user management solution. Prior to version 5.0.9, Role::stopMembership() does not verify whether removing a user from the administrator role leaves zero administrators. The deprecated Membership::stopMembership() contains this safety check, but the current code path bypasses it. Any administrator can remove the last remaining other administrator, locking the entire system out of administrative access. The exploit does not require concurrent requests; sequential removals produce the same result. This issue has been patched in version 5.0.9.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-754

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 3 classified signals
  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-05-07: 3Technical Details · 2026-05-07: 205-07
Signal classification1 categories
Disclosure
3100.0%
Referenced assets3 URLs
Full discourse3 posts
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-41662 📊 Severity: 5.2 🚨 Risk Level: Medium 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-41662 #CVE-2026-41662 #CVE #Medium #CyberSecurity #InfoSec https://t.co/mpZhJfqKDD

    Post summary

    The tweet announces a newly identified CVE-2026-41662 with medium severity (5.2), linking only to the NVD for more details and providing no further technical or exploit information.

    0000052
    152 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-41662 Admidio is an open-source user management solution. Prior to version 5.0.9, Role::stopMembership() does not verify whether removing a user from the administrator role… https://www.cve.org/CVERecord?id=CVE-2026-41662

    Post summary

    The post announces CVE‑2026‑41662 as a privilege‑escalation flaw in Admidio’s Role::stopMembership() before version 5.0.9, noting that the function fails to verify removal of administrator roles.

    0000092
    57.4K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-41662 Privilege Escalation in Admidio Prior to Version 5.0.9 via Administrator Removal https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-41662

    Post summary

    The post announces CVE‑2026‑41662 as a privilege escalation flaw in Admidio before version 5.0.9, attainable by removing administrator privileges.

    0000032
    4.0K followersView on X

Explore more