CVE-2026-41670Disclosure

LOWCVSS 8.2 · HIGH

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Admidio is an open-source user management solution. Prior to version 5.0.9, the SAML IdP implementation in Admidio's SSO module uses the AssertionConsumerServiceURL value directly from incoming SAML AuthnRequest messages as the destination for the SAML response, without validating it against the registered ACS URL (smc_acs_url) stored in the database for the corresponding service provider client. An attacker who knows the Entity ID of a registered SP client can craft a SAML AuthnRequest with an arbitrary AssertionConsumerServiceURL, causing the IdP to send the signed SAML response -- containing user identity attributes (login name, email, roles, profile fields) -- to an attacker-controlled URL. This issue has been patched in version 5.0.9.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-20CWE-601

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-05-07: 3Technical Details · 2026-05-07: 305-07
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets3 URLs
Full discourse3 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-41670 SAML Response Redirect Vulnerability in Admidio SSO Module Before 5.0.9 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-41670

    Post summary

    CVE-2026-41670 is a SAML response redirect vulnerability affecting Admidio's SSO module prior to v5.0.9; the entry includes only technical details without any PoC, exploit, or patch information.

    0001049
    4.0K followersView on X
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-41670 📊 Severity: 8.2 🚨 Risk Level: High 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-41670 #CVE-2026-41670 #CVE #High #CyberSecurity #InfoSec https://t.co/QwrWg35nis

    Post summary

    The tweet simply announces CVE-2026-41670 with an 8.2 CVSS score, providing no further detail about exploitation, patches, or technical specifics beyond the severity and affected products.

    0000057
    155 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-41670 Admidio is an open-source user management solution. Prior to version 5.0.9, the SAML IdP implementation in Admidio's SSO module uses the AssertionConsumerServiceURL v… https://www.cve.org/CVERecord?id=CVE-2026-41670

    Post summary

    The notice references CVE-2026-41670, noting a flaw in Admidio’s SAML IdP prior to version 5.0.9 related to the AssertionConsumerServiceURL; it contains no PoC, exploit code, active‑exploitation claim, or patch information.

    00000113
    57.4K followersView on X

Explore more