CVE-2026-32816: 
PHP vulnerability analysis and mitigation

Overview

CVE-2026-32816 is a Cross-Site Request Forgery (CSRF) vulnerability in Admidio, an open-source user management solution, affecting the role management module (modules/groups-roles/groups_roles.php). The delete, activate, and deactivate operations on organizational roles fail to validate the anti-CSRF token on the server side, allowing an attacker to forge destructive requests against authenticated users with role-assignment privileges. Affected versions are 5.0.0 through 5.0.6; the issue is patched in version 5.0.7. It carries a CVSS v3.1 base score of 5.7 (Medium) (GitHub Advisory).

Technical details

The root cause (CWE-352) is that while the client-side UI passes adm_csrf_token in the POST body via callUrlHideElement(), the server-side handlers for the delete, activate, and deactivate modes in groups_roles.php never call SecurityUtils::validateCsrfToken($_POST["adm_csrf_token"]), unlike the save mode which is properly protected. The only server-side validation performed is a UUID format check on $getRoleUUID, which prevents SQL injection but provides no CSRF protection. An attacker can harvest role UUIDs without authentication from the publicly accessible cards view (where UUIDs appear as HTML element IDs), then embed a forged auto-submitting POST form on an external page targeting groups_roles.php?mode=delete&role_uuid=<UUID> — no CSRF token field is required for the request to succeed (GitHub Advisory).

Impact

Successful exploitation allows an attacker to permanently delete organizational roles, which cascades to irrecoverable removal of all associated memberships, event associations, role dependency rules, and per-module access rights — with no soft-delete or undo path short of a full database restore. An attacker can also silently activate or deactivate entire groups, stripping access to events, document folders, mailing lists, and custom profile fields for all affected members simultaneously. The attack requires tricking only a user with the delegated rol_assign_roles right (e.g., a volunteer coordinator or department head), not a full system administrator, broadening the pool of viable victims (GitHub Advisory).

Exploitability

A proof-of-concept exploit is publicly available in the GitHub Security Advisory, including concrete curl commands and auto-submitting HTML forms that achieve permanent role deletion on a live Admidio instance without supplying a CSRF token. There is no evidence of in-the-wild exploitation at this time, and the vulnerability is not listed in the CISA KEV catalog. The EPSS score is approximately 0.014% (0.000140), reflecting low current exploitation probability (GitHub Advisory).

Exploitation steps

  1. Reconnaissance — Collect role UUIDs without authentication: Send a GET request to the public cards view to enumerate all role UUIDs from the HTML source:

    curl "https://TARGET/adm_program/modules/groups-roles/groups_roles.php?mode=cards"

    Role UUIDs appear as id="role_<UUID>" attributes and in action data attributes in the page source.

  2. Identify a victim: Identify a user account that holds the rol_assign_roles right (e.g., a group manager or committee chair). This does not require full administrator access.

  3. Forge a deletion request (direct test): Confirm the vulnerability by sending a POST request with the victim's session cookie and no CSRF token:

    curl -X POST \
      "https://TARGET/adm_program/modules/groups-roles/groups_roles.php?mode=delete&role_uuid=ROLE_UUID" \
      -H "Cookie: ADMIDIO_SESSION_ID=victim_session" \
      -d ""

    A {"status":"success"} response confirms the role is permanently deleted.

  4. CSRF delivery — Host a forged page: Create an auto-submitting HTML form on an attacker-controlled external page targeting the victim's Admidio instance with the harvested role UUID. When any authenticated user with rol_assign_roles visits the page, the browser automatically submits the forged POST request, permanently deleting the targeted role and all associated memberships and access rights without any user confirmation (GitHub Advisory).

Indicators of compromise

  • Network: Unexpected POST requests to /adm_program/modules/groups-roles/groups_roles.php with mode=delete, mode=activate, or mode=deactivate query parameters originating from unusual referrer origins (non-Admidio domains) or with empty/missing adm_csrf_token POST body fields.
  • Logs: Web server access logs showing POST requests to groups_roles.php?mode=delete or groups_roles.php?mode=deactivate with a Referer header pointing to an external domain; successful {"status":"success"} responses for role deletion requests.
  • Application/Database: Sudden disappearance of organizational roles from the Admidio database; mass removal of membership records (TBL_MEMBERS) or access-right entries (TBL_ROLES_RIGHTS_DATA) without corresponding administrator activity in audit logs; events with dat_rol_id set to NULL unexpectedly.

Mitigation and workarounds

Upgrade Admidio to version 5.0.7 or later, which adds SecurityUtils::validateCsrfToken($_POST["adm_csrf_token"]) at the start of each vulnerable case (delete, activate, deactivate) in groups_roles.php (Admidio Release, GitHub Advisory). As interim workarounds for deployments that cannot immediately upgrade: restrict public access to the groups-roles module to prevent unauthenticated UUID harvesting, and limit the rol_assign_roles right to only the most trusted administrators to reduce the pool of viable CSRF victims.

Additional resources


Source: This report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55224HIGH8.7
  • PHP logoPHP
  • mineadmin/mineadmin
NoYesSep 30, 2026
CVE-2026-103111HIGH7.6
  • MariaDB Server logoMariaDB Server
  • mariadb11.8-server
NoYesSep 30, 2026
GHSA-3q6v-r5mr-hxv8HIGH7.5
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
GHSA-97jj-33gv-5xf9MEDIUM6.1
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
CVE-2026-104181MEDIUM5.4
  • PHP logoPHP
  • filament/filament
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management