CVE-2026-82658: Admidio

Medium severity, CVSS 4.3. EPSS: 0.3% chance of exploitation in the next 30 days.

Admidio versions before 5.0.12 contain a broken access control vulnerability in profile_function.php that allows authenticated low-privilege users to read another user's future role memberships. Attackers can bypass profile-level authorization by directly calling the reload_future_memberships endpoint with a victim's user UUID to disclose sensitive membership information.

Affected products

  • Admidio Admidio: before 5.0.12 (fixed in 5.0.12)

Published 2026-08-30. Last modified 2026-09-02.