{"id":"CVE-2026-69093","title":"Admidio before 5.0.11 does not validate the adm_csrf_token in modules/category-report/preferences.php, which performs persistent Category Report configuration changes based on GET parameters (delete and copy)","summary":"Admidio before 5.0.11 does not validate the adm_csrf_token in modules/category-report/preferences.php, which performs persistent Category Report configuration changes based on GET parameters (delete and copy). An attacker can trick an au…","severity":"medium","cvss":4.6,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:L","cwe":["CWE-352"],"published":"2026-08-03","updated":"2026-09-09","sourceUpdated":"2026-09-09T20:35:08.537","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-69093","references":[{"url":"https://github.com/Admidio/admidio/commit/e1fe6fd2fcafb6a65a550760f79447abdef31461","label":"disclosure@vulncheck.com"},{"url":"https://github.com/Admidio/admidio/security/advisories/GHSA-mvx3-m6p6-7r9w","label":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/admidio-before-csrf-via-category-report-preferences","label":"disclosure@vulncheck.com"},{"url":"https://github.com/Admidio/admidio/security/advisories/GHSA-mvx3-m6p6-7r9w","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"tags":["nvd"],"epss":0.00128,"epssPercentile":0.02831,"ingestedAt":"2026-09-09T21:22:45.521Z","slug":"CVE-2026-69093","body":"## Overview\n\nAdmidio before 5.0.11 does not validate the adm_csrf_token in modules/category-report/preferences.php, which performs persistent Category Report configuration changes based on GET parameters (delete and copy). An attacker can trick an authenticated administrator into visiting a crafted URL to delete or duplicate Category Report configurations, affecting the integrity and availability of that module's configuration.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":25,"depthScoreParts":{"impact":25.3,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}