Admidio is an open-source user management solution. Prior to version 5.0.9, a logic error in Admidio's two-factor authentication reset inverts the authorization check. Non-admin users cannot remove their own TOTP configuration, but they can remove other users' TOTP, including administrators. A group leader with profile edit rights on an admin account can strip that admin's 2FA. This issue has been patched in version 5.0.9.
References
Configurations
No configuration.
History
07 May 2026, 14:51
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-05-07 04:16
Updated : 2026-05-07 14:51
NVD link : CVE-2026-41660
Mitre link : CVE-2026-41660
CVE.ORG link : CVE-2026-41660
JSON object : View
Products Affected
No product.
CWE
CWE-863
Incorrect Authorization
