CVE-2026-69094: Admidio before 5.0.11 contains an insecure direct object reference vulnerability in the save_temporary mode of mylist_function.php that allows authenticated users to hijack list co
Admidio before 5.0.11 contains an insecure direct object reference vulnerability in the save_temporary mode of mylist_function.php that allows authenticated users to hijack list configurations. Attackers can enumerate global list UUIDs and overwrite admin-curated global lists or other users' private lists by supplying a list_uuid parameter, transferring ownership and demoting global lists to personal configurations.
Details
Original advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-69094
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-69094 | coverage & exploitation status | NVD · CVE.org |
Recent advisories for Admidio
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- mediumCVE-2026-69093: Admidio before 5.0.11 does not validate the adm_csrf_token in modules/category-report/preferen…nvd · 2026-08-03
- mediumCVE-2026-69092: Admidio versions before 5.0.11 contain a reflected cross-site scripting vulnerability in the S…nvd · 2026-08-03
- highCVE-2026-69091: Admidio before 5.0.11 contains an authentication bypass vulnerability in the forum module when…nvd · 2026-08-03
- mediumCVE-2026-69090: Admidio before 5.0.11 fails to validate target organization membership in role handlers, allow…nvd · 2026-08-03
- mediumGHSA-hm42-q32m-vj4f: Admidio: CSRF on Plugin Install, Uninstall, and Update via Unprotected GET Requestsghsa · 2026-07-09
More from NVD Recent CVEs
- unknownCVE-2026-9487: XML::Sig versions before 0.71 for Perl allow signature wrapping via duplicate ID. _get_signed_x…2026-08-03
- unknownCVE-2026-9390: XML::Sig versions before 0.71 for Perl allow XPath injection in ID lookup. verify() and _get_si…2026-08-03
- highCVE-2026-69097: GitPython before 3.1.53 fails to properly escape section names in git config files, allowing a…2026-08-03
- highCVE-2026-69096: OpenWrt luci-app-dockerman (LuCI master and openwrt-25.12 snapshots containing the ucode docke…2026-08-03
- highCVE-2026-69095: OpenWrt luci-app-bmx7 before commit 5890760a454dad2cb00389dba2cdc5e779e0ffdd contains a path t…2026-08-03