
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-32817 is a Missing Authorization and CSRF Protection vulnerability in Admidio's documents and files module that allows unauthenticated attackers to permanently delete folders and files via plain HTTP GET requests. It affects Admidio versions 5.0.0 through 5.0.6 and was published on March 20, 2026, with a fix released in version 5.0.7. The vulnerability carries a CVSS v3.1 base score of 9.1 (Critical) (GitHub Advisory).
The root cause is CWE-862 (Missing Authorization): the folder_delete and file_delete action handlers in modules/documents-files.php only perform a VIEW-level authorization check (getFolderForDownload / getFileForDownload) before invoking the destructive delete() method, and they never validate a CSRF token. Target UUIDs are read directly from $_GET parameters, meaning any HTTP GET request — including one triggered by an embedded image tag — can invoke deletion. When documents_files_module_enabled = 1 (public mode) and a folder has fol_public = true, the getFolderForDownload function returns true without any login, granting unauthenticated access to the delete path. In contrast, all other write operations in the module route through DocumentsService, which properly validates CSRF tokens via getFormObject($_POST['adm_csrf_token']) — the delete handlers bypass this service entirely (GitHub Advisory).
In public mode with publicly marked folders, an unauthenticated remote attacker can permanently destroy the entire document library of an organization with a single GET request, since Folder::delete() recursively removes all sub-folders and files from both the database and the physical filesystem with no soft-delete or recovery mechanism. Even when the module is restricted to authenticated members only, any user with view-only access can delete content they are not permitted to modify, effectively escalating their privileges from read to delete. Additionally, because deletion is triggered by a GET request with no token, attackers can embed CSRF payloads in phishing emails or web pages to trigger deletion on behalf of any logged-in victim. There is no confidentiality impact, but integrity and availability impacts are both rated High (GitHub Advisory).
A proof-of-concept exploit is publicly available in the GitHub Security Advisory, including concrete curl commands and a GET-based CSRF image tag payload that can trigger unauthenticated data destruction on a real target system (GitHub Advisory). The EPSS score is 0.051% (0.000510), indicating a currently low probability of widespread exploitation. No in-the-wild exploitation or threat actor attribution has been reported at this time, and the vulnerability is not listed in the CISA KEV catalog (Feedly).
https://TARGET/adm_program/modules/documents-files.php?mode=list without credentials.curl "https://TARGET/adm_program/modules/documents-files.php?mode=folder_delete&folder_uuid=<FOLDER_UUID>"Expected response: {"status":"success"}. The folder, all sub-folders, and all files are permanently deleted.curl "https://TARGET/adm_program/modules/documents-files.php?mode=file_delete&file_uuid=<FILE_UUID>" \
-H "Cookie: ADMIDIO_SESSION_ID=<SESSION_COOKIE>"<img src="https://TARGET/adm_program/modules/documents-files.php?mode=folder_delete&folder_uuid=<FOLDER_UUID>">The victim's browser automatically sends the request with their session cookie attached (GitHub Advisory)./adm_program/modules/documents-files.php with mode=folder_delete or mode=file_delete parameters from unauthenticated or low-privilege sessions; requests originating from unusual IP addresses or user agents (e.g., curl).folder_uuid or file_uuid parameters returning HTTP 200 with {"status":"success"} responses; repeated deletion requests in a short time window.adm_folders, adm_files) without corresponding admin activity in audit logs (GitHub Advisory).Upgrade Admidio to version 5.0.7 or later, which adds proper authorization checks and CSRF token validation to both folder_delete and file_delete handlers. If immediate patching is not possible, disable the documents and files module entirely (set documents_files_module_enabled = 0) or switch it to members-only mode (= 2) and ensure no sensitive folders are marked public. Additionally, restrict network access to the Admidio instance to trusted users until the patch is applied (GitHub Advisory).
The Hacker Wire published coverage of the vulnerability highlighting the critical unauthorized deletion risk in Admidio 5.0.0–5.0.6 (The Hacker Wire). The advisory was published by the Admidio maintainer (Fasse) on GitHub on March 15, 2026, with a detailed technical breakdown and recommended code fixes (GitHub Advisory). No significant broader community or social media discussion has been identified beyond standard vulnerability database aggregation.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."