---
id: CVE-2026-34383
title: Admidio is an open-source user management solution
summary: >-
  Admidio is an open-source user management solution. Prior to version 5.0.8,
  the inventory module's item_save endpoint accepts a user-controllable POST
  parameter imported that, when set to true, completely bypasses both CSRF token
  validat…
severity: medium
cvss: 4.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'
cwe:
  - CWE-20
  - CWE-352
vendor: admidio
product: admidio
affected:
  - admidio < 5.0.8
patched:
  - admidio 5.0.8
published: '2026-03-31'
updated: '2026-10-06'
sourceUpdated: '2026-10-06T22:10:00.247'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-34383'
references:
  - url: >-
      https://github.com/Admidio/admidio/commit/00494b95dfe847af8b938e4397e5d909d8f36839
    label: security-advisories@github.com
  - url: 'https://github.com/Admidio/admidio/security/advisories/GHSA-4rwm-c5mj-wh7x'
    label: security-advisories@github.com
tags:
  - nvd
epss: 0.00151
epssPercentile: 0.03673
ingestedAt: '2026-10-06T22:23:15.911Z'
---

## Overview

Admidio is an open-source user management solution. Prior to version 5.0.8, the inventory module's item_save endpoint accepts a user-controllable POST parameter imported that, when set to true, completely bypasses both CSRF token validation and server-side form validation. An authenticated user can craft a direct POST request to save arbitrary inventory item data without CSRF protection and without the field value checks that the FormPresenter validation normally enforces. This issue has been patched in version 5.0.8.

## Affected

- `admidio < 5.0.8`

## Remediation

Upgrade past the affected range:

- `admidio 5.0.8`
