Improper Check for Unusual or Exceptional Conditions in Admidio - CVE-2026-41662
Published: April 23, 2026
Admidio
Detailed vulnerability description
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to improper check for unusual or exceptional conditions in Role::stopMembership() when removing a user from the administrator role. A remote privileged user can send a crafted membership removal request to cause a denial of service.
User interaction is required, and exploitation requires two active administrator accounts with valid sessions.