CVE-2026-41669Disclosure

LOWCVSS 8.2 · HIGH

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Admidio is an open-source user management solution. Prior to version 5.0.9, the Admidio SAML Identity Provider implementation discards the return value of its validateSignature() method at both call sites (handleSSORequest() line 418 and handleSLORequest() line 613). The method returns error strings on failure rather than throwing exceptions, but the developer believed it would throw (per comments on lines 416 and 611). This means the smc_require_auth_signed configuration option is completely ineffective — unsigned or invalidly-signed SAML AuthnRequests and LogoutRequests are processed identically to properly signed ones. This issue has been patched in version 5.0.9.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-347

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-05-07: 3Patch / Workaround · 2026-05-07: 1Technical Details · 2026-05-07: 205-07
Signal classification3 categories
Disclosure
133.3%
General
133.3%
Patch
133.3%
Referenced assets3 URLs
Full discourse3 posts
  • CVEarity@CVEarity
    General

    ⚡ New CVE Alert: CVE-2026-41669 📊 Severity: 8.2 🚨 Risk Level: High 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-41669 #CVE-2026-41669 #CVE #High #CyberSecurity #InfoSec https://t.co/xDHAis5Ge0

    Post summary

    The tweet announces CVE‑2026‑41669 with a severity rating but lacks any detailed technical, exploit, or remediation information.

    0000055
    152 followersView on X
  • CVE@CVEnew
    Patch

    CVE-2026-41669 Admidio is an open-source user management solution. Prior to version 5.0.9, the Admidio SAML Identity Provider implementation discards the return value of its validat… https://www.cve.org/CVERecord?id=CVE-2026-41669

    Post summary

    CVE-2026-41669 describes a flaw in Admidio's SAML IDP where it discards validation return values, which is purportedly fixed in version 5.0.9.

    00000101
    57.4K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-41669 SAML Signature Validation Bypass in Admidio Prior to Version 5.0.9 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-41669

    Post summary

    The snippet announces CVE-2026-41669, describing a SAML signature validation bypass in Admidio versions before 5.0.9, indicating a newly disclosed vulnerability.

    0000041
    4.0K followersView on X

Explore more