MEDIUMVulnerability
CVE-2026-69090
Admidio before 5.0.11 fails to validate target organization membership in role handlers, allowing authenticated role administrators to delete, activate, deactivate, or edit roles belonging to other organizations. Attackers can supply a role UUID from another organization to groups_roles.php handlers to modify that organization's roles without authorization.
Properties
- severity
- MEDIUM
- score
- 4.9
- epss_score
- 0.00201
- cve_id
- CVE-2026-69090
- vector
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N
- published_at
- 2026-08-03T14:16:29.580
- last_modified
- 2026-09-09T20:35:08.537
- epss_percentile
- 0.10004
Related Entities (3)
ENRICHED_BY (1)
→[Source]FIRST EPSS
DESCRIBED_BY (1)
→[Source]NVD
HAS_WEAKNESS (1)
→[Weakness]Missing Authorization
Explore deeper with Ninja Signal's threat intelligence graph