GitHub Security Advisory (GHSA-fcq9-w4hp-xchg)Vendor advisory
https://github.com/Admidio/admidio/security/advisories/GHSA-fcq9-w4hp-xchg CVE-2026-69090
MEDIUM
Admidio before 5.0.11 Cross-Organization Role Modification
Record summary
CVE-2026-69090 has a selected CVSS score of 6.9 (medium).
Description
Admidio before 5.0.11 fails to validate target organization membership in role handlers, allowing authenticated role administrators to delete, activate, deactivate, or edit roles belonging to other organizations. Attackers can supply a role UUID from another organization to groups_roles.php handlers to modify that organization's roles without authorization.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationPoC
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 3, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
admidioBrowse Admidio / admidioDefault status: unaffected | CVE List | Before 5.0.11 | affected |
| 5.0.11 | unaffected |
References
3nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2026-69090 VulnCheck Advisory: Admidio before 5.0.11 Cross-Organization Role ModificationThird-party advisory
https://www.vulncheck.com/advisories/admidio-before-cross-organization-role-modification