
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-32816 is a Cross-Site Request Forgery (CSRF) vulnerability in Admidio, an open-source user management solution, affecting the role management module (modules/groups-roles/groups_roles.php). The delete, activate, and deactivate operations on organizational roles fail to validate the anti-CSRF token on the server side, allowing an attacker to forge destructive requests against authenticated users with role-assignment privileges. Affected versions are 5.0.0 through 5.0.6; the issue is patched in version 5.0.7. It carries a CVSS v3.1 base score of 5.7 (Medium) (GitHub Advisory).
The root cause (CWE-352) is that while the client-side UI passes adm_csrf_token in the POST body via callUrlHideElement(), the server-side handlers for the delete, activate, and deactivate modes in groups_roles.php never call SecurityUtils::validateCsrfToken($_POST["adm_csrf_token"]), unlike the save mode which is properly protected. The only server-side validation performed is a UUID format check on $getRoleUUID, which prevents SQL injection but provides no CSRF protection. An attacker can harvest role UUIDs without authentication from the publicly accessible cards view (where UUIDs appear as HTML element IDs), then embed a forged auto-submitting POST form on an external page targeting groups_roles.php?mode=delete&role_uuid=<UUID> — no CSRF token field is required for the request to succeed (GitHub Advisory).
Successful exploitation allows an attacker to permanently delete organizational roles, which cascades to irrecoverable removal of all associated memberships, event associations, role dependency rules, and per-module access rights — with no soft-delete or undo path short of a full database restore. An attacker can also silently activate or deactivate entire groups, stripping access to events, document folders, mailing lists, and custom profile fields for all affected members simultaneously. The attack requires tricking only a user with the delegated rol_assign_roles right (e.g., a volunteer coordinator or department head), not a full system administrator, broadening the pool of viable victims (GitHub Advisory).
A proof-of-concept exploit is publicly available in the GitHub Security Advisory, including concrete curl commands and auto-submitting HTML forms that achieve permanent role deletion on a live Admidio instance without supplying a CSRF token. There is no evidence of in-the-wild exploitation at this time, and the vulnerability is not listed in the CISA KEV catalog. The EPSS score is approximately 0.014% (0.000140), reflecting low current exploitation probability (GitHub Advisory).
Reconnaissance — Collect role UUIDs without authentication: Send a GET request to the public cards view to enumerate all role UUIDs from the HTML source:
curl "https://TARGET/adm_program/modules/groups-roles/groups_roles.php?mode=cards"Role UUIDs appear as id="role_<UUID>" attributes and in action data attributes in the page source.
Identify a victim: Identify a user account that holds the rol_assign_roles right (e.g., a group manager or committee chair). This does not require full administrator access.
Forge a deletion request (direct test): Confirm the vulnerability by sending a POST request with the victim's session cookie and no CSRF token:
curl -X POST \
"https://TARGET/adm_program/modules/groups-roles/groups_roles.php?mode=delete&role_uuid=ROLE_UUID" \
-H "Cookie: ADMIDIO_SESSION_ID=victim_session" \
-d ""A {"status":"success"} response confirms the role is permanently deleted.
CSRF delivery — Host a forged page: Create an auto-submitting HTML form on an attacker-controlled external page targeting the victim's Admidio instance with the harvested role UUID. When any authenticated user with rol_assign_roles visits the page, the browser automatically submits the forged POST request, permanently deleting the targeted role and all associated memberships and access rights without any user confirmation (GitHub Advisory).
/adm_program/modules/groups-roles/groups_roles.php with mode=delete, mode=activate, or mode=deactivate query parameters originating from unusual referrer origins (non-Admidio domains) or with empty/missing adm_csrf_token POST body fields.groups_roles.php?mode=delete or groups_roles.php?mode=deactivate with a Referer header pointing to an external domain; successful {"status":"success"} responses for role deletion requests.TBL_MEMBERS) or access-right entries (TBL_ROLES_RIGHTS_DATA) without corresponding administrator activity in audit logs; events with dat_rol_id set to NULL unexpectedly.Upgrade Admidio to version 5.0.7 or later, which adds SecurityUtils::validateCsrfToken($_POST["adm_csrf_token"]) at the start of each vulnerable case (delete, activate, deactivate) in groups_roles.php (Admidio Release, GitHub Advisory). As interim workarounds for deployments that cannot immediately upgrade: restrict public access to the groups-roles module to prevent unauthenticated UUID harvesting, and limit the rol_assign_roles right to only the most trusted administrators to reduce the pool of viable CSRF victims.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."