---
id: CVE-2026-69090
title: >-
  Admidio before 5.0.11 fails to validate target organization membership in role
  handlers, allowing authenticated role administrators to delete, activate,
  deactivate, or edit roles belonging to other organizations
summary: >-
  Admidio before 5.0.11 fails to validate target organization membership in role
  handlers, allowing authenticated role administrators to delete, activate,
  deactivate, or edit roles belonging to other organizations. Attackers can
  supply a r…
severity: medium
cvss: 4.9
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N'
cwe:
  - CWE-862
published: '2026-08-03'
updated: '2026-09-09'
sourceUpdated: '2026-09-09T20:35:08.537'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-69090'
references:
  - url: 'https://github.com/Admidio/admidio/security/advisories/GHSA-fcq9-w4hp-xchg'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/admidio-before-cross-organization-role-modification
    label: disclosure@vulncheck.com
  - url: 'https://github.com/Admidio/admidio/security/advisories/GHSA-fcq9-w4hp-xchg'
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
epss: 0.00242
epssPercentile: 0.15724
ingestedAt: '2026-09-09T21:22:45.521Z'
---

## Overview

Admidio before 5.0.11 fails to validate target organization membership in role handlers, allowing authenticated role administrators to delete, activate, deactivate, or edit roles belonging to other organizations. Attackers can supply a role UUID from another organization to groups_roles.php handlers to modify that organization's roles without authorization.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
