Improper Authentication in Admidio - CVE-2026-41671
Published: April 23, 2026
Admidio
Detailed vulnerability description
The vulnerability allows a remote attacker to bypass authentication on connected resource servers.
The vulnerability exists due to improper authentication in the OIDC token introspection endpoint when processing token validation requests. A remote attacker can submit a fabricated, expired, revoked, or empty token to bypass authentication on connected resource servers.
The issue affects the /modules/sso/index.php/oidc/introspect endpoint and has changed scope because the vulnerable authorization server can cause unauthorized access decisions in connected resource servers.