What is CVE-2026-69093?
This vulnerability in Admidio versions prior to 5.0.11 stems from a missing CSRF token validation in modules/category-report/preferences.php, allowing persistent Category Report configuration changes via GET parameters (delete and copy). An attacker can exploit this by tricking an authenticated administrator into visiting a crafted URL, leading to unauthorized deletion. Users are urged to upgrade to version 5.0.11 or later immediately.
Azərbaycanca: Bu boşluq Admidio 5.0.11-dən əvvəlki versiyalarda "CSRF token" doğrulamasının olmaması səbəbindən yaranır. "modules/category-report/preferences.php" faylında "GET" parametrləri ilə kateqoriya hesabat konfiqurasiyasını dəyişmək mümkündür, bu da autentifikasiya olunmuş administratoru hazırlanmış URL-i ziyarət etməyə aldadaraq məlumatların silinməsinə səbəb ola bilər. Dərhal 5.0.11 və ya daha yuxarı versiyaya yeniləmə etmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-352; shared vendor: Admidio
FAQ2
What is the core technical flaw that causes the CVE-2026-69093 vulnerability in Admidio?
The vulnerability stems from a missing CSRF token validation in `modules/category-report/preferences.php`, allowing unauthorized Category Report configuration changes via `GET` parameters.
Which version is recommended to upgrade to in order to protect against CVE-2026-69093?
It is recommended to immediately upgrade to Admidio version 5.0.11 or later.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.