MEDIUMVulnerability

CVE-2026-69090

Admidio before 5.0.11 fails to validate target organization membership in role handlers, allowing authenticated role administrators to delete, activate, deactivate, or edit roles belonging to other organizations. Attackers can supply a role UUID from another organization to groups_roles.php handlers to modify that organization's roles without authorization.

Properties

severity
MEDIUM
score
4.9
epss_score
0.00201
cve_id
CVE-2026-69090
vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N
published_at
2026-08-03T14:16:29.580
last_modified
2026-09-09T20:35:08.537
epss_percentile
0.10004

Related Entities (3)

ENRICHED_BY (1)

[Source]FIRST EPSS

DESCRIBED_BY (1)

[Source]NVD

HAS_WEAKNESS (1)

[Weakness]Missing Authorization

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-69090 — Ninja Signal Threat Intelligence | Ninja Signal