Admidio before 5.0.11 contains an insecure direct object reference vulnerability in the save_temporary mode of mylist_function.php that allows… (CVE-2026-69094)
Admidio versions before 5.0.11 have an insecure direct object reference vulnerability in the save_temporary mode of mylist_function.php. Authenticated users can exploit this flaw to hijack list configurations by enumerating global list UUIDs and overwriting admin-curated global lists or other users' private lists. This allows attackers to transfer ownership and demote global lists to personal configurations. The vulnerability has a CVSS 3.1 score of 4.3, indicating medium severity.
AI Analysis
Technical Summary
The vulnerability in Admidio prior to version 5.0.11 is an insecure direct object reference (CWE-639) in the save_temporary mode of mylist_function.php. Authenticated attackers can enumerate global list UUIDs and supply a crafted list_uuid parameter to overwrite global or private lists. This results in unauthorized modification of list ownership and configuration, potentially disrupting administrative controls over global lists.
Potential Impact
The vulnerability allows authenticated users to modify or hijack list configurations that they should not have access to, including admin-curated global lists and other users' private lists. This can lead to unauthorized changes in list ownership and demotion of global lists to personal configurations. There is no indication of confidentiality or availability impact, only integrity is affected.
Mitigation Recommendations
A fix is available in Admidio version 5.0.11. Users should upgrade to version 5.0.11 or later to remediate this vulnerability. No other mitigation guidance is provided or required.
Admidio before 5.0.11 contains an insecure direct object reference vulnerability in the save_temporary mode of mylist_function.php that allows… (CVE-2026-69094)
Description
Admidio versions before 5.0.11 have an insecure direct object reference vulnerability in the save_temporary mode of mylist_function.php. Authenticated users can exploit this flaw to hijack list configurations by enumerating global list UUIDs and overwriting admin-curated global lists or other users' private lists. This allows attackers to transfer ownership and demote global lists to personal configurations. The vulnerability has a CVSS 3.1 score of 4.3, indicating medium severity.
CVSS v3.1
Score 4.3medium
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability in Admidio prior to version 5.0.11 is an insecure direct object reference (CWE-639) in the save_temporary mode of mylist_function.php. Authenticated attackers can enumerate global list UUIDs and supply a crafted list_uuid parameter to overwrite global or private lists. This results in unauthorized modification of list ownership and configuration, potentially disrupting administrative controls over global lists.
Potential Impact
The vulnerability allows authenticated users to modify or hijack list configurations that they should not have access to, including admin-curated global lists and other users' private lists. This can lead to unauthorized changes in list ownership and demotion of global lists to personal configurations. There is no indication of confidentiality or availability impact, only integrity is affected.
Mitigation Recommendations
A fix is available in Admidio version 5.0.11. Users should upgrade to version 5.0.11 or later to remediate this vulnerability. No other mitigation guidance is provided or required.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-mmp5-653m-6rjv
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-69094"]
- Ecosystems
- []
- Database Specific Severity
- MODERATE
- Cvss Version
- 3.1
Threat ID: 6a710666bf32cb7a34394d81
Added to database: 08/03/2026, 21:21:42 UTC
Last enriched: 08/03/2026, 21:32:39 UTC
Last updated: 08/03/2026, 22:57:48 UTC
Views: 2
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.