CVE-2026-69094
Received Received - Intake

Insecure Direct Object Reference in Admidio Before 5.0.11

Vulnerability report for CVE-2026-69094, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-03

Last updated on: 2026-08-03

Assigner: VulnCheck

Description

Admidio before 5.0.11 contains an insecure direct object reference vulnerability in the save_temporary mode of mylist_function.php that allows authenticated users to hijack list configurations. Attackers can enumerate global list UUIDs and overwrite admin-curated global lists or other users' private lists by supplying a list_uuid parameter, transferring ownership and demoting global lists to personal configurations.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-03
Last Modified
2026-08-03
Generated
2026-08-03
AI Q&A
2026-08-03
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
admidio admidio to 5.0.11 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-639 The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Admidio before version 5.0.11 has an insecure direct object reference vulnerability in the save_temporary mode of mylist_function.php. This allows authenticated users to hijack list configurations by exploiting a list_uuid parameter. Attackers can enumerate global list UUIDs and overwrite admin-curated global lists or other users' private lists, transferring ownership and demoting global lists to personal configurations.

Detection Guidance

Check for unauthorized modifications to list configurations in Admidio by reviewing logs for requests to mylist_function.php with save_temporary mode and list_uuid parameters. Look for unusual enumeration of global list UUIDs or changes to list ownership.

Impact Analysis

If you use Admidio before 5.0.11, an attacker with authenticated access could modify your list configurations. This could lead to unauthorized changes in shared or personal lists, potentially causing data loss, misinformation, or disruption of collaborative features.

Compliance Impact

This vulnerability could impact compliance by allowing unauthorized modifications to sensitive data stored in lists. For GDPR, it may lead to unauthorized data access or alteration. For HIPAA, it could compromise protected health information integrity. Organizations must ensure proper access controls and patch systems to maintain compliance.

Mitigation Strategies

Upgrade Admidio to version 5.0.11 or later to patch the vulnerability. Review and restrict access to mylist_function.php, especially the save_temporary mode. Monitor list configurations for unauthorized changes and enforce strict access controls.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-69094. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart