CVE-2026-34384Medium· 4.5▾ SunlitAdmidio is an open-source user management solution. Prior to version 5.0.8, the create_user, assign_member, and assign_user action modes in modules/registration.php approve pending user registrations via GET request without validating a …
▾ Sunlit zone — Low / medium · no exploitation signal
impact 24.8 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.2%
Admidio is an open-source user management solution. Prior to version 5.0.8, the create_user, assign_member, and assign_user action modes in modules/registration.php approve pending user registrations via GET request without validating a CSRF token. Unlike the delete_user mode in the same file (which correctly validates the token), these three approval actions read their parameters from $_GET and perform irreversible state changes without any protection. An attacker who has submitted a pending registration can extract their own user UUID from the registration confirmation email URL, then trick any user with the rol_approve_users right into visiting a crafted URL that automatically approves the registration. This bypasses the manual registration approval workflow entirely. This issue has been patched in version 5.0.8.
admidio < 5.0.8Upgrade past the affected range:
admidio 5.0.8Connected by shared product, vendor, weakness, or advisory.
CVE-2026-34382Medium· 4.6Admidio is an open-source user management solution
CVE-2026-34383Medium· 4.3Admidio is an open-source user management solution
CVE-2026-53760Medium· 5.2Admidio is an open-source user management solution
CVE-2026-34381High· 7.5Admidio is an open-source user management solution
CVE-2026-47230Medium· 6.5Admidio is an open-source user management solution
CVE-2026-47227Medium· 6.5Admidio is an open-source user management solution