What is CVE-2026-47233?
This vulnerability was identified in Admidio, an open-source user management solution. Although version 5.0.9 added the missing `isAdministratorInventory()` gate for 'item_delete' in `modules/inventory.php`, the same fix was not applied to the 'field_delete' handler, allowing non-admin users to delete an entire inventory field definition. Updating to a patched version is strongly recommended.
Azərbaycanca: Bu, Admidio açıq mənbəli istifadəçi idarəetmə sistemində müəyyən edilmiş zəiflikdir. Versiya 5.0.9-da 'item_delete' üçün əlavə olunan `isAdministratorInventory()` yoxlaması `field_delete` funksiyasına tətbiq edilmədiyi üçün, admin olmayan istifadəçi bütün inventar sahə tərifini silə bilər. Dərhal müvafiq versiyaya yeniləmə etmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-863; shared vendor: Admidio
FAQ2
What platform does CVE-2026-47233 affect?
This vulnerability affects the Admidio open-source user management system.
How to protect against CVE-2026-47233?
Updating to a patched version is strongly recommended.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.