Improper access control in Admidio - CVE-2026-34383
Published: April 23, 2026
Admidio
Detailed vulnerability description
The vulnerability allows a remote user to bypass form validation.
The vulnerability exists due to improper access control in the inventory item save functionality when handling requests with the imported parameter. A remote user can send a specially crafted request to bypass form validation.
The issue is related to cross-site request forgery handling in the inventory item save process.