PT-2026-37144 · Admidio · Admidio

Adrgs

·

Published

2026-04-29

·

Updated

2026-05-07

·

CVE-2026-41660

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L
Name of the Vulnerable Software and Affected Versions Admidio versions prior to 5.0.9
Description A logic error in the two-factor authentication (2FA) reset process inverts the authorization check. This allows non-admin users to remove the Time-based One-Time Password (TOTP) configuration of other users, including administrators, while preventing them from removing their own. Specifically, a group leader with profile edit rights on an admin account can strip that admin's 2FA, reducing the account security to password-only authentication. The issue exists in the 'modules/profile/two factor authentication.php' file, where an inverted condition in the authorization check fails to block non-admins from resetting other users' 2FA. The vulnerable endpoint is '/adm program/modules/profile/two factor authentication.php' using the mode and user uuid parameters.
Recommendations Update to version 5.0.9. As a temporary workaround, restrict the hasRightEditProfile() permission for group leaders to minimize the risk of unauthorized 2FA removal.

Exploit

Fix

Incorrect Authorization

Weakness Enumeration

Related Identifiers

CVE-2026-41660
GHSA-RH3W-4CCX-PRF9

Affected Products

Admidio