CVE-2026-41663Disclosure

LOWCVSS 3.5 · LOW

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Admidio is an open-source user management solution. Prior to version 5.0.9, several administrative operations in Admidio's preferences module (database backup, test email, htaccess generation) fire via GET requests with no CSRF token validation. Because SameSite=Lax cookies travel with top-level GET navigations, an attacker forces an authenticated admin to trigger these actions from a malicious page. This issue has been patched in version 5.0.9.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-352

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-05-07: 3Technical Details · 2026-05-07: 105-07
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets4 URLs
Full discourse3 posts
  • CVEarity@CVEarity
    General

    ⚡ New CVE Alert: CVE-2026-41663 📊 Severity: 3.5 🚨 Risk Level: Low 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-41663 #CVE-2026-41663 #CVE #Low #CyberSecurity #InfoSec https://t.co/E0Nfc9Igpx

    Post summary

    The tweet only announces the existence of CVE-2026-41663 with a low severity score and a link to its NVD entry, lacking any technical details, PoC, or evidence of exploitation.

    0000064
    152 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-41663 Admidio is an open-source user management solution. Prior to version 5.0.9, several administrative operations in Admidio's preferences module (database backup, test e… https://www.cve.org/CVERecord?id=CVE-2026-41663

    Post summary

    Admidio’s preferences module had an administrative‑operation vulnerability prior to version 5.0.9, as recorded in CVE‑2026‑41663.

    00000100
    57.4K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-41663 Cross-Site Request Forgery in Admidio Preferences Module Before V... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-41663 Customizable Vulnerability Alerts: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=4

    Post summary

    The tweet announces CVE‑2026‑41663, a CSRF flaw in Admidio’s Preferences module prior to a certain version, linking to a vulnerability details page but offering no PoC, exploit code, active exploitation evidence, or patch information.

    0000036
    4.0K followersView on X

Explore more