Junglewise Threat Intelligence

CVE-2026-47234: Admidio sensitive information disclosure in application logs

CVE-2026-47234 · Severity: medium · CVSS 4.4 · Published 2026-05-29

Technologies: admidio/admidio (Packagist), Admidio. Vendors: Packagist, Admidio.

Executive brief

Admidio, a web-based membership management system, contains a security flaw where it records sensitive user login information into its system logs. When debug mode is enabled, the software writes active session IDs and persistent 'remember me' tokens in plain text to the log files. An individual with access to these logs—such as a system administrator or an attacker who has gained limited server access—could use this information to hijack user accounts and gain unauthorized access to the organization's data.

Technical details

Admidio versions 5.0.9 and earlier are vulnerable to sensitive information disclosure in the logging component. When debug logging is enabled, the `Session::setCookie()` and `Session::start()` methods in `src/Session/Entity/Session.php` write raw cookie values and session IDs to the application log. This includes the `ADMIDIO_*_SESSION_ID` and the persistent `ADMIDIO_*_AUTO_LOGIN_ID`. An attacker with read access to the log files, backups, or log aggregation services can extract these bearer tokens to perform session hijacking or maintain long-term unauthorized access to user accounts. The issue is addressed in version 5.0.10 by redacting these sensitive values before they are committed to the logs.

Affected products

  • Admidio Admidio <= 5.0.9

Timeline

  • 2026-05-25: disclosed
  • 2026-05-29: advisory: GHSA-mch8-wf3h-6x88 published

References

Related threats