CVE-2026-82658

Admidio versions before 5.0.12 contain a broken access control vulnerability in profile_function.php that allows authenticated low-privilege users to read another user's future role memberships. Attackers can bypass profile-level authorization by directly calling the reload_future_memberships endpoint with a victim's user UUID to disclose sensitive membership information.
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-30 15:16

Updated : 2026-09-02 16:17


NVD link : CVE-2026-82658

Mitre link : CVE-2026-82658

CVE.ORG link : CVE-2026-82658


JSON object : View

Products Affected

No product.

CWE
CWE-285

Improper Authorization