


Perceptive Security
SOC/SIEM Consultancy

Admidio before 5.0.11 contains an authentication bypass vulnerability in the forum module when configured in login-only mode. The access control logic in module…
Published:
2 augustus 2026 om 22:00:00
Alert date:
3 augustus 2026 om 15:06:10
Source:
nvd.nist.gov
Web Technologies, Identity & Access
Admidio versions before 5.0.11 contain an authentication bypass vulnerability in the forum module. When the application is configured in login-only mode, the access control logic in modules/forum.php fails to properly validate the login-only configuration state. This flaw allows unauthenticated attackers to read forum topics and posts by directly accessing the module with read-only parameters. The vulnerability effectively bypasses the intended access restriction, exposing potentially sensitive forum content to unauthorized users. A fix is available in Admidio version 5.0.11 and later. The issue has been documented in the official GitHub security advisory and tracked by VulnCheck.
Technical details
Mitigation steps:
Affected products:
Admidio
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-69091
https://github.com/Admidio/admidio/security/advisories/GHSA-cf48-6jrq-gjcm
https://www.vulncheck.com/advisories/admidio-before-authentication-bypass-via-forum-php
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
