Input validation error in Admidio - CVE-2026-41670
Published: April 23, 2026
Admidio
Detailed vulnerability description
The vulnerability allows a remote attacker to disclose sensitive information and impersonate a user at a service provider.
The vulnerability exists due to improper input validation in the SAML IdP implementation in src/SSO/Service/SAMLService.php when processing SAML AuthnRequest messages. A remote attacker can send a crafted AuthnRequest with an attacker-controlled AssertionConsumerServiceURL to disclose sensitive information and impersonate a user at a service provider.
User interaction is required, and exploitation is possible without signature verification when the service provider client uses the default settings for request signing validation.