Beveiligingsadvies

CVE-2026-82658

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-08-30 14:33:38
Laatst bijgewerkt 2026-09-02 15:59:16
Toegewezen door VulnCheck
CVSS-score 5.3
Status PUBLISHED

Beschrijving

Admidio versions before 5.0.12 contain a broken access control vulnerability in profile_function.php that allows authenticated low-privilege users to read another user's future role memberships. Attackers can bypass profile-level authorization by directly calling the reload_future_memberships endpoint with a victim's user UUID to disclose sensitive membership information.