CVE-2026-69094 Details
Description
Admidio before 5.0.11 contains an insecure direct object reference vulnerability in the save_temporary mode of mylist_function.php that allows authenticated users to hijack list configurations. Attackers can enumerate global list UUIDs and overwrite admin-curated global lists or other users' private lists by supplying a list_uuid parameter, transferring ownership and demoting global lists to personal configurations.
A vulnerability allowing insecure direct object reference has been identified in Admidio versions prior to 5.0.11. This vulnerability resides in the 'save_temporary' mode of 'mylist_function.php', where authenticated users can hijack list configurations. The issue arises because the 'save_temporary' mode does not verify ownership or administrative rights before overwriting list data. As a result, attackers can manipulate global list UUIDs, replacing administrator-managed global lists or other users' private lists by sending a 'list_uuid' parameter. This exploitation transfers ownership of the list to the attacker and demotes the list's status from global to personal, effectively removing it from the visibility of other users.
Users are advised to update Admidio to version 5.0.11 or later, where this vulnerability has been patched.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Aug 3, 2026CISA-ADP
Assessed Aug 3, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/Admidio/admidio/security/advisories/GHSA-rw2j-8c57-x6h2 | CISA-ADP | AdvisoryTechnical AnalysisVendor |
| https://github.com/Admidio/admidio/security/advisories/GHSA-rw2j-8c57-x6h2 | [email protected] | AdvisoryTechnical AnalysisVendor |
| https://www.vulncheck.com/advisories/admidio-before-idor-via-save-temporary-mylist-function-php | [email protected] | Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-639 | Authorization Bypass Through User-Controlled Key | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Admidio | <= 5.0.10 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 3, 2026 | CVE Modified | CISA-ADP |
| Aug 3, 2026 | New CVE Received | [email protected] |
Volerion