AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-47227

MEDIUM · CVSS 6.5 EPSS 0.24% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-12 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

Admidio's user management solution contains a vulnerability in the `modules/categories.php` file, where improper validation allows users with limited module-administrator rights to delete or reorder categories belonging to other modules. This flaw arises from dead code that prevents proper checks on category editability, potentially leading to unauthorized data manipulation. Organizations utilizing Admidio prior to version 5.0.10 should prioritize patching to mitigate the risk of unauthorized access and data integrity issues.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-47227
Severity
MEDIUM
CVSS
6.5
EPSS
0.24%

Original NVD Description

Admidio is an open-source user management solution. `modules/categories.php` checks that the supplied `type` parameter (`ANN`, `EVT`, `ROL`, `USF`, …) corresponds to a module the actor administers. The follow-up "is this specific category editable by me" check at lines 56-61 is dead code because it compares `$getType` (a category-type code) against mode names (`edit`/`save`/`delete`); the condition is permanently false, so `$category->isEditable()` is never invoked. Prior to version 5.0.10, the `delete`, `sequence`, and `save` switch cases load the category by the supplied UUID and act on it without re-checking that the category belongs to a module the actor administers. A user holding only one module-administrator right can therefore destroy or reorder empty categories belonging to *other* modules — for example, an announcements administrator can delete role categories, profile-field categories, or weblink categories that they have no right to touch. Version 5.0.10 fixes the issue.