Vulnerability Description
Admidio is an open-source user management solution. Prior to version 5.0.9, the add mode in modules/documents-files.php accepts a name parameter validated only as 'string' type (HTML encoding), allowing path traversal characters (../) to pass through unfiltered. Combined with the absence of CSRF protection on this endpoint and SameSite=Lax session cookies, a low-privileged attacker can trick a documents administrator into clicking a crafted link that registers an arbitrary server file (e.g., install/config.php containing database credentials) into a documents folder accessible to the attacker. This issue has been patched in version 5.0.9.
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
- https://github.com/Admidio/admidio/releases/tag/v5.0.9
- https://github.com/Admidio/admidio/security/advisories/GHSA-m9h6-8pqm-xrhf
- https://github.com/Admidio/admidio/security/advisories/GHSA-m9h6-8pqm-xrhf
FAQ
What is CVE-2026-41656?
CVE-2026-41656 is a vulnerability with a CVSS score of 4.5 (MEDIUM). Admidio is an open-source user management solution. Prior to version 5.0.9, the add mode in modules/documents-files.php accepts a name parameter validated only as 'string' type (HTML encoding), allowi...
How severe is CVE-2026-41656?
CVE-2026-41656 has been rated MEDIUM with a CVSS base score of 4.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-41656?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.