CVE-2026-32755: 
PHP vulnerability analysis and mitigation

Overview

CVE-2026-32755 is a Cross-Site Request Forgery (CSRF) vulnerability in Admidio, an open-source user management system, affecting the role membership date change functionality. The vulnerability exists in all versions up to and including 5.0.6 of the admidio/admidio Composer package, and was disclosed on March 15, 2026, with a patch released the same day in version 5.0.7. It carries a CVSS v3.1 base score of 5.7 (Moderate) (GitHub Advisory, Admidio Advisory).

Technical details

The root cause (CWE-352) is an incomplete CSRF token validation in modules/profile/profile_function.php. The CSRF guard only covers the stop_membership and remove_former_membership action modes, but omits save_membership from the validation array — meaning the server never checks the adm_csrf_token for that action, even though the form generates one. An attacker who can view any Admidio profile page (any authenticated user) can extract the user_uuid and member_uuid values from the HTML source, then craft a malicious POST form targeting /adm_program/modules/profile/profile_function.php?mode=save_membership&user_uuid=<VICTIM_USER_UUID>&member_uuid=<MEMBERSHIP_UUID> and trick a role leader into submitting it. No CSRF token is required in the forged request because the server-side handler does not validate it for this mode (Admidio Advisory).

Impact

Successful exploitation allows an attacker to silently manipulate role membership start and end dates for any member of roles led by the CSRF victim. Setting an end date to a past value immediately terminates a member's active participation, revoking their access to role-restricted features such as events, document folders with upload rights, and mailing list memberships. Conversely, an attacker could extend a membership period beyond its authorized end date to covertly maintain access for a user who should have been deactivated. All changes occur without any confirmation dialog or notification email, making detection difficult (Admidio Advisory).

Exploitability

A proof-of-concept HTML exploit payload is publicly available in the GitHub Security Advisory, consisting of a self-submitting POST form that requires no CSRF token (Admidio Advisory). There is no evidence of in-the-wild exploitation at this time, and no threat actor attribution has been reported. The EPSS score is approximately 0.017% (1st percentile), indicating a low near-term exploitation probability (GitHub Advisory). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog.

Exploitation steps

  1. Reconnaissance: As an authenticated Admidio user, browse to the profile page of a target member whose membership you wish to manipulate. Inspect the HTML source to extract the user_uuid and member_uuid values embedded in the membership date form's action URL (/adm_program/modules/profile/profile_function.php?mode=save_membership&user_uuid=<VALUE>&member_uuid=<VALUE>).
  2. Identify a CSRF victim: Identify a role leader (or role administrator) who has allowedToAssignMembers() rights over the target member's role — these are regular members designated as group leaders, representing a low-privilege attack surface.
  3. Craft the malicious form: Create an HTML page hosted on an attacker-controlled server containing a POST form targeting the vulnerable endpoint with the extracted UUIDs and desired date values (e.g., adm_membership_start_date=2000-01-01 and adm_membership_end_date=2000-01-02 to immediately terminate membership). No adm_csrf_token field is needed.
  4. Deliver the payload: Trick the role leader into visiting the attacker-controlled page while logged into Admidio (e.g., via phishing email or malicious link). The form auto-submits via JavaScript (document.getElementById('csrf_form').submit()).
  5. Achieve objective: The server processes the forged POST request using the victim's authenticated session, overwrites the target member's membership dates, and returns success — silently revoking or extending the member's access with no notification sent (Admidio Advisory).

Indicators of compromise

  • Network: Unexpected POST requests to /adm_program/modules/profile/profile_function.php?mode=save_membership originating from unusual referrer domains (non-Admidio origins) in web server access logs.
  • Logs: Web server logs showing POST requests to the save_membership endpoint with a Referer header pointing to an external or unknown domain; absence of the adm_csrf_token field in the POST body for save_membership requests.
  • Application: Membership date changes (especially end dates set to historical dates like 2000-01-01) recorded in the Admidio database without a corresponding user-initiated action; membership changes occurring outside normal business hours or from unexpected IP addresses.
  • User Reports: Members unexpectedly losing access to role-restricted events, document folders, or mailing lists without any administrative action being taken through the normal UI (Admidio Advisory).

Mitigation and workarounds

Admidio released version 5.0.7 on March 15, 2026, which addresses this vulnerability by adding save_membership to the existing CSRF token validation check in modules/profile/profile_function.php. All users running Admidio 5.0.6 or earlier should upgrade to version 5.0.7 or later immediately (Admidio Release). As a defense-in-depth measure, administrators should also consider configuring SameSite=Strict or SameSite=Lax cookie attributes on session cookies to reduce CSRF risk, and enabling audit logging for membership date changes (Admidio Advisory).

Additional resources


Source: This report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55224HIGH8.7
  • PHP logoPHP
  • mineadmin/mineadmin
NoYesSep 30, 2026
CVE-2026-103111HIGH7.6
  • MariaDB Server logoMariaDB Server
  • mariadb11.8-server
NoYesSep 30, 2026
GHSA-3q6v-r5mr-hxv8HIGH7.5
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
GHSA-97jj-33gv-5xf9MEDIUM6.1
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
CVE-2026-104181MEDIUM5.4
  • PHP logoPHP
  • filament/filament
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management