CVE-2026-41660

Admidio is an open-source user management solution. Prior to version 5.0.9, a logic error in Admidio's two-factor authentication reset inverts the authorization check. Non-admin users cannot remove their own TOTP configuration, but they can remove other users' TOTP, including administrators. A group leader with profile edit rights on an admin account can strip that admin's 2FA. This issue has been patched in version 5.0.9.
Configurations

No configuration.

History

07 May 2026, 14:51

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-07 04:16

Updated : 2026-05-07 14:51


NVD link : CVE-2026-41660

Mitre link : CVE-2026-41660

CVE.ORG link : CVE-2026-41660


JSON object : View

Products Affected

No product.

CWE
CWE-863

Incorrect Authorization