CVE-2026-41671Disclosure

LOWCVSS 6.8 · MEDIUM

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Admidio is an open-source user management solution. Prior to version 5.0.9, the OIDC token introspection endpoint (/modules/sso/index.php/oidc/introspect) always returns {"active": true} for every request, regardless of whether a valid token is provided, whether the token is expired, revoked, or completely fabricated. The endpoint performs no authentication of the calling resource server and no validation of the submitted token. Any resource server that relies on this introspection endpoint to validate access tokens will accept all requests as authorized, enabling complete authentication bypass. Additionally, the OIDC token revocation endpoint (/oidc/revoke) returns {"revoked": true} without actually revoking any token, preventing resource servers from invalidating compromised credentials. This issue has been patched in version 5.0.9.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-287

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 3 classified signals
  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-05-07: 3Technical Details · 2026-05-07: 205-07
Signal classification1 categories
Disclosure
3100.0%
Referenced assets3 URLs
Full discourse3 posts
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-41671 📊 Severity: 6.8 🚨 Risk Level: Medium 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-41671 #CVE-2026-41671 #CVE #Medium #CyberSecurity #InfoSec https://t.co/YPjsIEisBP

    Post summary

    The tweet announces a new CVE-2026‑41671, lists its severity and risk level, but provides no exploit, patch, or detailed technical information.

    0000062
    155 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-41671 Admidio is an open-source user management solution. Prior to version 5.0.9, the OIDC token introspection endpoint (/modules/sso/index.php/oidc/introspect) always retu… https://www.cve.org/CVERecord?id=CVE-2026-41671

    Post summary

    The post announces the CVE‑2026‑41671 vulnerability in Admidio, noting a problematic OIDC introspection endpoint prior to v5.0.9, without providing PoC, exploit code, or patches.

    00000120
    57.4K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-41671 Authentication Bypass in Admidio OIDC Token Introspection Endpoint Before 5.0.9 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-41671

    Post summary

    The text announces an authentication bypass in Admidio’s OIDC token introspection endpoint for versions prior to 5.0.9, providing basic technical details but no PoC, exploit, patch, or active exploitation evidence.

    0000042
    4.0K followersView on X

Explore more