CVE-2026-34381High· 7.5▾ TwilightAdmidio is an open-source user management solution. From version 5.0.0 to before version 5.0.8, Admidio relies on adm_my_files/.htaccess to deny direct HTTP access to uploaded documents. The Docker image ships with AllowOverride None in …
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.5%
Admidio is an open-source user management solution. From version 5.0.0 to before version 5.0.8, Admidio relies on adm_my_files/.htaccess to deny direct HTTP access to uploaded documents. The Docker image ships with AllowOverride None in the Apache configuration, which causes Apache to silently ignore all .htaccess files. As a result, any file uploaded to the documents module regardless of the role-based permissions configured in the UI, is directly accessible over HTTP without authentication by anyone who knows the file path. The file path is disclosed in the upload response JSON. This issue has been patched in version 5.0.8.
admidio >= 5.0.0, < 5.0.8Upgrade past the affected range:
admidio 5.0.8Connected by shared product, vendor, weakness, or advisory.
CVE-2026-34384Medium· 4.5Admidio is an open-source user management solution
CVE-2026-34382Medium· 4.6Admidio is an open-source user management solution
CVE-2026-34383Medium· 4.3Admidio is an open-source user management solution
CVE-2026-47230Medium· 6.5Admidio is an open-source user management solution
CVE-2026-47227Medium· 6.5Admidio is an open-source user management solution
CVE-2026-53760Medium· 5.2Admidio is an open-source user management solution