What is CVE-2026-69090?
This vulnerability in Admidio before 5.0.11 involves a failure to validate target organization membership in role handlers. An authenticated role administrator can supply a role UUID from another organization to `groups_roles.php` handlers, allowing them to delete, activate, deactivate, or edit roles belonging to other organizations. Users should upgrade to Admidio version 5.0.11 or later.
Azərbaycanca: Bu zəiflik Admidio-nun 5.0.11-dən əvvəlki versiyalarında rol idarəetmə funksiyalarında təşkilat üzvlüyünün yoxlanılmaması ilə bağlıdır. Autentifikasiya olunmuş rol administratoru başqa təşkilata məxsus rolun UUID-sini `groups_roles.php` emalçılarına ötürərək həmin rolları silə, aktivləşdirə, deaktiv edə və ya redaktə edə bilər. İstifadəçilər Admidio-nu 5.0.11 və ya daha yeni versiyaya yeniləməlidir.
Related CVEs
link basis: same weakness class CWE-863; shared vendor: Admidio
FAQ2
Which versions of Admidio are affected by CVE-2026-69090?
This vulnerability affects all versions of Admidio prior to 5.0.11.
What can an authenticated role administrator do by exploiting CVE-2026-69090?
An authenticated role administrator can supply a role UUID from another organization to `groups_roles.php` handlers, allowing them to delete, activate, deactivate, or edit roles belonging to other organizations.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.