Loading market data...
← Back to CVE feed

CVE-2026-82658

MEDIUM CVSS 4.3 View on NVD ↗

Description

Admidio versions before 5.0.12 contain a broken access control vulnerability in profile_function.php that allows authenticated low-privilege users to read another user's future role memberships. Attackers can bypass profile-level authorization by directly calling the reload_future_memberships endpoint with a victim's user UUID to disclose sensitive membership information.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Published: Aug 30, 2026 15:16 UTC Modified: Aug 30, 2026 15:16 UTC