Admidio is an open-source user management solution. Prior to version 5.0.9, the Admidio inventory module enforces authorization for destructive operations (delete, retire, reinstate) only in the UI layer by conditionally rendering buttons. The backend POST handlers at modules/inventory.php for item_delete, item_retire, item_reinstate, item_picture_upload, item_picture_save, and item_picture_delete perform CSRF validation but never check whether the requesting user is an inventory administrator. Any authenticated user who can access the inventory module can permanently delete any inventory item and all its associated data. This issue has been patched in version 5.0.9.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-05-07 04:16
Updated : 2026-06-17 10:46
NVD link : CVE-2026-41658
Mitre link : CVE-2026-41658
CVE.ORG link : CVE-2026-41658
JSON object : View
Products Affected
No product.
CWE
CWE-862
Missing Authorization
