CVE-2026-82657

Admidio before 5.0.12 fails to enforce login-only module restrictions in RSS feed endpoints for forum and announcements modules. Unauthenticated attackers can retrieve forum topics and announcements by sending GET requests to rss/forum.php or rss/announcements.php, disclosing titles, full post text, author names, and timestamps.
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-30 15:16

Updated : 2026-08-31 20:56


NVD link : CVE-2026-82657

Mitre link : CVE-2026-82657

CVE.ORG link : CVE-2026-82657


JSON object : View

Products Affected

No product.

CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor