CVE-2026-30927: 
PHP vulnerability analysis and mitigation

Overview

CVE-2026-30927 is an Insecure Direct Object Reference (IDOR) / authorization bypass vulnerability in Admidio, an open-source user management solution. It affects all versions prior to 5.0.6 (including the <= 4.3 branch) and was disclosed on March 7, 2026, with a patch released in version 5.0.6. The flaw resides in modules/events/events_function.php, where the event participation logic fails to restrict non-leader users from acting on behalf of other users by manipulating the user_uuid GET parameter. It carries a CVSS v3.1 base score of 5.4 (Medium) and a CVSS v4.0 base score of 5.3 (Medium) (Github Advisory, Admidio Advisory).

Technical details

The root cause is CWE-639 (Authorization Bypass Through User-Controlled Key). In modules/events/events_function.php, the user_uuid value is read directly from the GET parameter (line 47: $getUserUuid = admFuncVariableIsValid($_GET, 'user_uuid', 'uuid', ...)) and the authorization check at line 424 uses an OR condition: if ($event->possibleToParticipate() || $participants->isLeader($gCurrentUserId)). Because the first condition is true for any open event, any authenticated user with participation rights can supply an arbitrary user_uuid belonging to another user, and the code will operate on that target user's usr_id rather than the current user's. The fix, applied in commit e47f70c, forces $getUserUuid to the current user's UUID for all non-leader users before any participation action is processed (Admidio Advisory, Patch Commit).

Impact

Successful exploitation allows an authenticated attacker to register arbitrary users for events without their consent (potential harassment or spam), cancel other users' legitimate event registrations, manipulate event participant counts and comments, and — if events have participation limits — fill available slots with unwanted registrations to deny access to legitimate participants. The impact is confined to integrity and availability of event participation records within the Admidio instance; there is no confidentiality impact and no pathway to lateral movement or remote code execution (Github Advisory, Admidio Advisory).

Exploitability

No public proof-of-concept exploit code has been observed, and there is no evidence of in-the-wild exploitation at this time. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.012–0.019%, indicating a very low near-term exploitation probability. Exploitation requires only a low-privilege authenticated account on an Admidio instance with at least one open event, making it technically straightforward for any registered user to attempt (Github Advisory).

Exploitation steps

  1. Authenticate: Log in to the target Admidio instance with any valid user account that has event participation privileges.
  2. Identify an open event: Browse to the events module and locate an event where possibleToParticipate() returns true (i.e., the event is open for registration).
  3. Enumerate target user UUIDs: Identify the user_uuid values of other registered users. These may be discoverable through the Admidio member directory, profile pages, or by observing existing participation records.
  4. Craft a malicious request: Construct a GET request to modules/events/events_function.php targeting the event participation endpoint, substituting the user_uuid parameter with the UUID of the victim user. For example: GET /admidio/modules/events/events_function.php?mode=participate&event_id=<ID>&user_uuid=<VICTIM_UUID>
  5. Submit the request: Send the crafted request. Because the OR condition in the authorization check passes (event is open), the server processes the action using the victim's usr_id, registering or cancelling their participation without their knowledge.
  6. Repeat or automate: Repeat for additional target users or events to fill participation slots, cancel legitimate registrations, or harass specific users (Admidio Advisory, Patch Commit).

Indicators of compromise

  • Network: HTTP GET requests to modules/events/events_function.php containing a user_uuid parameter that does not match the authenticated session user's UUID; repeated participation/cancellation requests from a single session targeting multiple different user_uuid values.
  • Logs: Web server access logs showing the same authenticated user account making rapid or repeated requests to the events participation endpoint with varying user_uuid values; unexpected event registration or cancellation entries in Admidio's activity/audit logs for users who did not initiate the action.
  • Application Data: Event participant lists showing users registered or deregistered without corresponding user-initiated actions; event slots filled unexpectedly or legitimate registrations cancelled without user confirmation.

Mitigation and workarounds

Upgrade Admidio to version 5.0.6 or later, which contains the fix applied in commit e47f70c. The patch enforces that non-leader users can only act on their own participation by overriding the user_uuid to the current user's UUID server-side. If immediate patching is not possible, consider temporarily disabling event participation functionality or restricting event participation to trusted user groups only. Monitor event participation logs for anomalous registration or cancellation activity as a compensating control (Admidio Advisory, Patch Commit).

Community reactions

The vulnerability was reported and fixed by the Admidio maintainer (Fasse) on March 7, 2026, with the GitHub security advisory and issue tracker entry published simultaneously. A brief write-up was noted on infinitsec.net shortly after disclosure. Overall community reaction has been minimal, consistent with the moderate severity and limited deployment footprint of Admidio (Admidio Advisory, GitHub Issue).

Additional resources


Source: This report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55224HIGH8.7
  • PHP logoPHP
  • mineadmin/mineadmin
NoYesSep 30, 2026
CVE-2026-103111HIGH7.6
  • MariaDB Server logoMariaDB Server
  • mariadb11.8-server
NoYesSep 30, 2026
GHSA-3q6v-r5mr-hxv8HIGH7.5
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
GHSA-97jj-33gv-5xf9MEDIUM6.1
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
CVE-2026-104181MEDIUM5.4
  • PHP logoPHP
  • filament/filament
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management