Junglewise Threat Intelligence

CVE-2026-47227: Admidio broken authorization in category management

CVE-2026-47227 · Severity: medium · CVSS 6.5 · Published 2026-05-29

Technologies: admidio/admidio (Packagist), Admidio. Vendors: Packagist, Admidio.

Executive brief

Admidio is a web-based membership management system. A security flaw allows users with limited administrative rights (such as a forum or announcement moderator) to delete or modify categories belonging to other parts of the system they should not have access to. This could result in the loss of organizational structure, such as the deletion of event calendars, role groupings, or profile field categories, requiring manual restoration from backups.

Technical details

A vulnerability exists in `modules/categories.php` due to a 'dead code' authorization check. The script validates that a user has rights for a specific module type (e.g., 'ANN' for announcements) but fails to verify if the specific category being modified (identified by UUID) actually belongs to that module. A logic error in an `in_array` check compares the category type against action modes ('edit', 'save', 'delete'), which always evaluates to false, bypassing the `$category->isEditable()` check. An attacker with any single module-admin privilege can perform POST requests to delete or modify categories of any other type. This is fixed in version 5.0.10.

Affected products

  • Admidio Admidio <= 5.0.9

Timeline

  • 2026-05-25: disclosed
  • 2026-05-29: advisory

References

Related threats