
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-32755 is a Cross-Site Request Forgery (CSRF) vulnerability in Admidio, an open-source user management system, affecting the role membership date change functionality. The vulnerability exists in all versions up to and including 5.0.6 of the admidio/admidio Composer package, and was disclosed on March 15, 2026, with a patch released the same day in version 5.0.7. It carries a CVSS v3.1 base score of 5.7 (Moderate) (GitHub Advisory, Admidio Advisory).
The root cause (CWE-352) is an incomplete CSRF token validation in modules/profile/profile_function.php. The CSRF guard only covers the stop_membership and remove_former_membership action modes, but omits save_membership from the validation array — meaning the server never checks the adm_csrf_token for that action, even though the form generates one. An attacker who can view any Admidio profile page (any authenticated user) can extract the user_uuid and member_uuid values from the HTML source, then craft a malicious POST form targeting /adm_program/modules/profile/profile_function.php?mode=save_membership&user_uuid=<VICTIM_USER_UUID>&member_uuid=<MEMBERSHIP_UUID> and trick a role leader into submitting it. No CSRF token is required in the forged request because the server-side handler does not validate it for this mode (Admidio Advisory).
Successful exploitation allows an attacker to silently manipulate role membership start and end dates for any member of roles led by the CSRF victim. Setting an end date to a past value immediately terminates a member's active participation, revoking their access to role-restricted features such as events, document folders with upload rights, and mailing list memberships. Conversely, an attacker could extend a membership period beyond its authorized end date to covertly maintain access for a user who should have been deactivated. All changes occur without any confirmation dialog or notification email, making detection difficult (Admidio Advisory).
A proof-of-concept HTML exploit payload is publicly available in the GitHub Security Advisory, consisting of a self-submitting POST form that requires no CSRF token (Admidio Advisory). There is no evidence of in-the-wild exploitation at this time, and no threat actor attribution has been reported. The EPSS score is approximately 0.017% (1st percentile), indicating a low near-term exploitation probability (GitHub Advisory). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog.
user_uuid and member_uuid values embedded in the membership date form's action URL (/adm_program/modules/profile/profile_function.php?mode=save_membership&user_uuid=<VALUE>&member_uuid=<VALUE>).allowedToAssignMembers() rights over the target member's role — these are regular members designated as group leaders, representing a low-privilege attack surface.adm_membership_start_date=2000-01-01 and adm_membership_end_date=2000-01-02 to immediately terminate membership). No adm_csrf_token field is needed.document.getElementById('csrf_form').submit()).success — silently revoking or extending the member's access with no notification sent (Admidio Advisory)./adm_program/modules/profile/profile_function.php?mode=save_membership originating from unusual referrer domains (non-Admidio origins) in web server access logs.save_membership endpoint with a Referer header pointing to an external or unknown domain; absence of the adm_csrf_token field in the POST body for save_membership requests.2000-01-01) recorded in the Admidio database without a corresponding user-initiated action; membership changes occurring outside normal business hours or from unexpected IP addresses.Admidio released version 5.0.7 on March 15, 2026, which addresses this vulnerability by adding save_membership to the existing CSRF token validation check in modules/profile/profile_function.php. All users running Admidio 5.0.6 or earlier should upgrade to version 5.0.7 or later immediately (Admidio Release). As a defense-in-depth measure, administrators should also consider configuring SameSite=Strict or SameSite=Lax cookie attributes on session cookies to reduce CSRF risk, and enabling audit logging for membership date changes (Admidio Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."